HomeSecurityMOVEit Transfer customers warned of new flaw

MOVEit Transfer customers warned of new flaw

Progress has warned MOVEit Transfer customers to restrict all HTTP access to their environment after information about a new SQL injection (SQLi) vulnerability was shared online yesterday.

MOVEit Transfer

A patch to address this new critical security flaw is not yet available, however, according to the company, such a patch is under testing and will be released soon.

“Progress has discovered a vulnerability in MOVEit Transfer that could lead to privilege escalation and possible unauthorized access to the environment,” Progress said.

“We have removed HTTPS traffic for MOVEit Cloud in light of the recently disclosed vulnerability and are asking all MOVEit Transfer customers to immediately remove HTTP and HTTPS traffic to protect environments while the fix is ​​completed,” it added.

See also: Android malware GravityRAT steals your WhatsApp backups

Until security updates are released for affected MOVEit Transfer versions, Progress recommends modifying firewall rules to deny HTTP and HTTPS traffic to MOVEit Transfer on ports 80 and 443 as a temporary workaround.

Although users will no longer be able to log in to their accounts via the web UI, file transfers will still be available, as the SFTP and FTP/s protocols will continue to work as expected.

Administrators can also access MOVEit Transfer by connecting to the Windows server via remote desktop and then going to https://localhost/.

While Progress did not share the location where the details of this new SQLi flaw were shared, at least one security researcher shared information on Twitter about what appears to be proof-of-concept exploit code for a new MOVEit Transfer zero-day flaw.

See also: Credential Theft: What is it and how to protect yourself?

The researcher told BleepingComputer that he believes this new warning from Progress is related to the PoC they are working on.

"I have not achieved RCE. This vulnerability is not a workaround for any previous vulnerability. It has its own attack path," the researcher added.

BleepingComputer has also learned that the vulnerability had already been disclosed to Progress, with the help of Huntress senior security researcher John Hammond. This disclosure likely prompted the company's warning.

Today's warning follows another advisory published on Friday, which disclosed critical SQL injection vulnerabilities tracked collectively as CVE-2023-35036 and discovered after a security audit that began on May 31, when Progress issued patches for a zero-day flaw (CVE-2023-34362) used by the Clop ransomware gang in data theft attacks.

CVE-2023-35036 affects all versions of MOVEit Transfer and allows unauthorized attackers to compromise unpatched and Internet-exposed servers, allowing them to steal customer information.

The Clop ransomware gang claimed responsibility for the CVE-2023-34362 attacks and told BleepingComputer that it had allegedly compromised the MOVEit servers of “hundreds of companies.”.

Kroll also found evidence that Clop has been testing exploits for the now-patched MOVEit zero-day since 2021 and ways to exfiltrate data stolen from compromised MOVEit servers since at least April 2022.

Clop has been linked to other high-profile campaigns targeting managed file transfer platforms, including the breach of Accellion FTA servers in December 2020, the SolarWinds Serv-U Managed File Transfer attacks in 2021, and the widespread exploitation of GoAnywhere MFT servers in January 2021.

MOVEit Transfer customers warned of new flaw

Affected orgs are being blackmailed

On Wednesday, the Clop gang began blackmailing organizations affected by the MOVEit data theft attacks by listing their names on the dark web data leak site.

Five of the listed companies—British multinational oil and gas company Shell, the University of Georgia (UGA) and the University System of Georgia (USG), UnitedHealthcare Student Resources (UHSR), Heidelberger Druck, and Landal Greenparks—have since confirmed to BleepingComputer that they were affected by the attacks.

Other organizations that have already disclosed MOVEit Transfer breaches include Zellis (and its customers BBC, Boots, Aer Lingus and HSE Ireland), Ofcam, the Government of Nova Scotia, the US state of Missouri, the US state of Illinois, the University of Rochester, the American Board of Internal Medicine, BORN Ontario and Extreme Networks.

Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) revealed that several U.S. federal agencies had been compromised, according to a report by CNN. Additionally, two U.S. Department of Energy (DOE) agencies were also breached, according to the Federal News Network.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS