HomeSecurityFBI and CISA: Hackers exploit critical Zoho bug

FBI and CISA: Hackers exploit critical Zoho bug

The FBI, CISA and the Government Administration of the Coast Guard (CGCYBER) warned today that state-supported persistent threat groups (APT) have been exploiting a critical bug in a Zoho system since August 2021.

See also: Patch Tuesday September 2021: Microsoft fixes critical bugs

Zoho

Zoho's client list includes “three of the five Fortune 500 companies”, including Apple, Intel, Nike, PayPal, HBO and many others.

The vulnerability , identified as CVE-2021-40539, was found in Zoho ManageEngine ADSelfService Plus software and allows attackers to "take over" vulnerable systems after a successful exploitation.

See also: Netgear: Fixes serious bugs in over a dozen smart switches

The attacks also target critical infrastructure organizations

This advisory follows a previous warning issued by CISA last week, which warned of CVE-2021-40539 which could allow threat actors to remotely execute malicious code on compromised systems

In incidents where exploits CVE-2021-40539 have been used, attackers were observed deploying a JavaServer Pages (JSP) web shell that is camouflaged as an x509 certificate.

This web shell is then used for lateral movement via Windows Management Instrumentation (WMI) to access domain controllers and dump the registry hives NTDS.dit and SECURITY/SYSTEM.

So far, the APT groups behind these attacks have targeted a broad range of sectors from academic institutions and defense contractors to critical infrastructure entities.

See also: Google app bug on Android causes call issues

Mitigation measures

Zoho released the Zoho ManageEngine ADSelfService Plus build 6114, which fixed the CVE-2021-40539 vulnerability on September 6.

In a subsequent security advisory, the company added that “it observes indications of exploitation of this vulnerability”.

The FBI, CISA, and CGCYBER urge organizations to immediately implement the updated version of ADSelfService Plus build 6114 and ensure that ADSelfService Plus is not directly accessible from the internet.

Organizations that detect malicious activity related to ManageEngineADSelfService Plus are advised to report it immediately as an incident to CISA or the FBI.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS