The Cybersecurity and Infrastructure Security Agency (CISA) has identified a remote code execution flaw in most Zoho ManageEngine products, which is already being exploited by malicious actors.
See also: Chinese hackers exploit zero-day vulnerability in Fortinet devices

Designated CVE-2022-47966, this security vulnerability was quickly resolved in several phases, starting on October 27, 2022.
If SAML-based single sign-on (SSO) is enabled or has been previously enabled, malicious actors can exploit this vulnerability to execute unauthorized code.
Over the past seven days, Horizon3 security experts have released a clear and comprehensive research with proof-of-concept (PoC) exploit code and warned of potential “spray and pray” attacks. To prevent malicious activity, they strongly encouraged everyone to take preventive measures.
See also: Microsoft plans to kill malware delivery via Excel XLL add-ins
It was revealed that 8,300 ServiceDesk Plus and Endpoint Central services were accessible online, while an estimated 10% of them are also vulnerable.
The next day, alerts from multiple cybersecurity companies stated that unprotected ManageEngine instances currently accessible online were under continuous attacks using CVE-2022-47966 exploits to open reverse shells.
Upon further investigation, Rapid7 security experts discovered that hackers are disabling malware protection in order to infiltrate machines by installing remote access tools. This post-exploit activity serves as incriminating evidence of the attackers ’ malicious intent .
All organizations are urged to prioritize patching
All Federal Executive Branch Agencies (FCEB) must patch their systems for a currently exploited vulnerability that was added to the Known Exploited Vulnerabilities (KEV) list by CISA via a binding business directive (BOD 22-01). This order is effective November 2021.
By February 13, federal agencies must take every precaution to ensure their networks are secure and impenetrable from potential cyberattacks. Time is precious - there is no room for procrastination!
Although BOD 22-01 only affects US FCEB organizations, the cybersecurity agency strongly recommended that all organizations in both the public and private sectors prioritize immediate patching of this vulnerability for security reasons.
Last month, the Cybersecurity and Infrastructure Security Agency (CISA) required federal agencies to address a critical security vulnerability (CVE-2022-35405) present in several Zoho ManageEngine products. Exploiting this flaw would give unauthorized individuals remote code execution access without requiring authentication.
See also: Google Ads invitations: Abused to spread malicious links
Since August, a Metasploit module and PoC exploit code have been made publicly available as tools to achieve RCE as a system user. This is in response to CVE-2022-35405.
In previous alerts, the FBI and CISA warned that government hacking groups are exploiting ManageEngine vulnerabilities to attack organizations across a wide range of critical infrastructure sectors, such as finance and healthcare.
An RCE bug is a type of software vulnerability that allows an attacker to remotely execute arbitrary code on any vulnerable system without authentication or authorization. An RCE bug can be exploited in a variety of ways—such as through network services, web applications, email attachments, or even operating systems—to gain access to sensitive data or take complete control of the targeted system.
Information source: bleepingcomputer.com
