HomeSecurityZoho RCE: Proof-of-Concept for dangerous bug released

Zoho RCE: Proof-of-Concept for dangerous bug released

Later this week, a Proof-of-Concept for a serious vulnerability , allowing unauthenticated remote code execution in multiple VMware. This devastating security flaw allows hackers to gain unauthorized access to the system and cause massive destruction.

See also: Zoho urges admins to immediately fix a ManageEngine bug

Zoho

CVE -2022-47966, is an RCE security vulnerability based on the use of a vulnerable and outdated third-party dependency of Apache Santuario.

RCE, or remote code execution, is a type of attack that allows an attacker to execute malicious code on a server, resulting in a complete compromise . This type of attack is possible when an application contains a vulnerability that the attacker can exploit. To successfully carry out an RCE attack, the attacker must first find a way to inject their malicious code into the vulnerable application. Once their code is executed, the attacker will have complete control of the system.

By exploiting the vulnerability, malicious actors can execute arbitrary code on ManageEngine without authentication if SAML-based single sign-on (SSO) was enabled at least once prior to the attack.

Countless ManageEngine products are vulnerable to this vulnerability. Fortunately, Zoho has released patches as of October 27, 2022, upgrading the version of the third-party module for better security.

On Friday, the Horizon3 attack team issued a stern warning to administrators about the proof-of-concept (PoC) exploit for CVE-2022-47966 they had created.

See also: FBI: Hackers exploit critical Zoho zero-day bug
RCE

This vulnerability is fairly easy to exploit and is a prime target for attackers who take a “spray and pray” approach across the Internet. As Horizon3 security researcher James Horseman, this security flaw allows remote code execution as NT AUTHORITY\SYSTEM, giving an attacker unfettered control over the system.

“When a user realizes they have been the victim of an attack, it is important to investigate the extent of the damage the attacker has caused. Once an attacker gains SYSTEM-level access to the endpoint, it is expected that they will attempt to exfiltrate credentials by exploiting LSASS or exploiting publicly available tools to access stored application credentials as a means of lateral movement.“

Although they have not yet released technical details and have only shared indicators of compromise (IOCs) to help defenders identify if their systems have been affected, Horizon3 plans to release the Proof-of-Concept exploit later this week.

Horizon3 researchers presented a screenshot depicting their exploit being run against an unprotected ManageEngine ServiceDesk Plus, providing proof of its capabilities.

See also: Hackers exploit a new Zoho ServiceDesk exploit

By investigating just two of ManageEngine's vulnerable products, ServiceDesk Plus and Endpoint Central, Horseman discovered thousands of unpatched servers that were publicly exposed online via Shodan.

Of the exposed ManageEngine products, a striking number had SAML enabled, leaving approximately 10% of them vulnerable to CVE-2022-47966 attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS