Critical RCE Vulnerability Reported in ConnectWise Server Backup Solution
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-36537 | Unauthenticated Information Disclosure in ZK Framework AuUploader ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 fail to properly handle requests to the AuUploader servlet component, allowing unauthenticated attackers to access sensitive information. The flaw is triggered by sending a crafted POST request to the AuUploader endpoint over the network; no privileges or user interaction are required, and per the CVSS vector the impact is limited to confidentiality (no tampering or denial of service). An attacker gains the ability to read sensitive data served by Java web applications built on the affected ZK releases, potentially yielding details that enable follow-on intrusions. Any organization running or hosting a web application that embeds one of the affected ZK Framework versions is exposed, including third-party products that bundle the framework. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-27 with known ransomware use and required federal agencies to apply vendor updates, and its top-percentile EPSS score of 95.3% indicates a very high likelihood of continued exploitation. Do: Upgrade ZK Framework to a patched release per vendor instructions, replacing the affected builds (8.6.4.1, 9.0.1.2, 9.5.1.3, 9.6.0.1 and 9.6.1). Inventory web applications and bundled products that use ZK, determine whether the AuUploader servlet is reachable, and restrict or filter access to that endpoint at the application server, reverse proxy, or WAF as an interim mitigation. Given the known ransomware-linked exploitation, prioritize patching internet-facing applications first. | 7.5 | 95% | KEV ransomware |
| large≈ tens of thousands of internet-exposed Java web applications embedding ZK (estimate) |
Full article308 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananNov 01, 2022
IT service management software platform ConnectWise has released Software patches for a critical security vulnerability in Recover and R1Soft Server Backup Manager (SBM).
The issue, characterized as a "neutralization of Special Elements in Output Used by a Downstream Component," could be abused to result in the execution of remote code or disclosure of sensitive information.
ConnectWise's advisory notes that the flaw affects Recover v2.9.7 and earlier, as well as R1Soft SBM v6.16.3 and earlier, are impacted by the critical flaw.
At its core, the issue is tied to an upstream authentication bypass vulnerability in the ZK open source Ajax web application framework (CVE-2022-36537), which was initially patched in May 2022.
"Affected ConnectWise Recover SBMs have automatically been updated to the latest version of Recover (v2.9.9)," the company said, urging customers to upgrade to SBM v6.16.4 shipped on October 28, 2022.
Cybersecurity firm Huntress said it identified "upwards of 5,000 exposed server manager backup instances," potentially exposing companies to supply chain risks.
While there is no evidence of active exploitation of the vulnerability in the wild, a proof-of-concept devised by Huntress researchers John Hammond and Caleb Stewart shows that it can be abused to bypass authentication, gain remote code execution on SBM, and push LockBit 3.0 ransomware to all downstream endpoints.
"It is important to note that the upstream ZK vulnerability not only affects R1Soft, but also any application utilizing an unpatched version of the ZK framework," the researchers said.
"The access an attacker can gain by using this authentication bypass vulnerability is specific to the application being exploited, however there is serious potential for other applications to be affected in a similar way to R1Soft Server Backup Manager."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/11/critical-rce-vulnerability-reported-in.html