Arcserve has fixed a high - severity vulnerability in bypass authentication its and gain administrative privileges. Unified Data Protection (UDP) backup software . The vulnerability could allow attackers to

According to the company, Arcserve UDP is a data protection solution designed to help customers attacks ransomware, restore compromised data, and enable smooth business continuity.
Arcserve released UDP version 9.1 to fix the vulnerability CVE-2023-26258on June 27. The vulnerability was discovered and reported four months earlier by security researchers Juan Manuel Fernandez and Sean Doherty of MDSec's ActiveBreach.
See also: Akira ransomware: Linux version targets VMware ESXi servers
“ During a recent simulation, the MDSec ActiveBreach team was executing a ransomware scenario, with the primary goal of compromising the organization’s backup infrastructure ,” the researchers said
“Within minutes of analyzing the code, a critical authentication bypass vulnerability was discovered that allowed access to the administration interface“.
On systems running Arcserve UDP 7.0 to 9.0, the vulnerability allows attackers on the local network to access the UDP admin interface after obtaining admin credentialsby logging SOAP requests containing AuthUUID, to obtain valid administrator sessions.
See also: Priorities in preparing for a ransomware attack: people, processes and technology

With admin credentials, attackers can destroy targets' data by deleting backups in ransomware.
MDSec ActiveBreach researchers added that default MSSQL database credentials could also be used to obtain admin credentials, if the targeted server has already been patched for CVE-2023-26258 but is using default config.
See also: Mobile Malware and mobile phishing sites increased in 2022
Researchers shared proof-of-concept exploits and tools that can be used to scan for Arcserve UDP instances with default configuration on local networks.
Source: www.bleepingcomputer.com
