HomeSecurityCrushFTP RCE chain: Exploit released, update now

CrushFTP RCE chain: Exploit released, update now

A Proof-of-Concept was recently published for a critical remote code execution (RCE) vulnerability in the CrushFTP enterprise suite, allowing unauthenticated attackers to gain access to files on the server, execute code, and obtain plaintext passwords.

See also: Atlassian: New exploit for data deletion bug in Confluence
CrushFTP

The vulnerability was discovered in August 2023 (CVE-2023-43177), by security researchers at Converge, who responsibly reported it to the vendor. The developers released a fix within a day in CrushFTP version 10.5.2.

Converge recently published a Proof-of-Concept exploit for the CVE-2023-43177, making it critical for CrushFTP users to install security updates as soon as possible.

The CrushFTP RCE exploit is done through an unauthorized bulk assignment vulnerability, exploiting the AS2 header parsing that checks the user's session properties. This allows attackers to read and delete files, potentially leading to full system control and remote root-level code execution

Attackers can send payloads to the CrushFTP service on specific ports (80, 443, 8080, 9090) using web headers, which leave footprints in the log files. The attackers then overwrite session data using Java 's ' putAll() ' function , enabling 'administrators' impersonation, and leverage the ' drain_log() ' function to spoof files during the attack, maintaining their presence unseen.

See also: VMware: Public exploitation of RCE flaw in vRealize

Finally, attackers can exploit the 'sessions.obj' file in the program's installation folder to compromise live user sessions belonging to administrator accounts, effectively achieving privilege escalation. Once they have gained administrator access, the attacker can exploit flaws in the SQL loader handling and the test database setup (testDB) of the administration panel to execute arbitrary Java code.

According to the Converge report, there are approximately 10,000 instances of CrushFTP visible to the public and likely many more behind corporate firewalls. The attack surface is significant, even if the number of vulnerable instances has not yet been determined.

RCE

File transfer products like CrushFTP are particularly attractive to ransomware perpetrators, especially Clop, which exploits zero-day in software like MOVEit Transfer, GoAnywhere MFT , and Accelion FTA to carry out data theft attacks.

Unfortunately, researchers revealed that even applying the updates does not fully secure CrushFTP endpoints from all potential threats.

See also: Education: Increased attacks through phishing and exploitation of vulnerabilities

The potential risks and consequences of not upgrading are multiple and serious. First, exploiting the vulnerability could gain remote access and control over your system. This means it could identify, change or delete data, execute malicious code , or cause damage to your system.

Second, the attacker can use your system as a gateway to attack other systems. This can lead to loss of confidential information, data theft, or even the breach of security of third parties.

Third, failure to upgrade can lead to a breach of compliance with data protection regulations and laws. This can have serious legal consequences, such as fines or even lawsuits from customers or other stakeholders.

Finally, not upgrading can lead to a loss of trust from your customers and users. When customers realize that your system is vulnerable to attacks, they may decide to move to other, more secure alternatives.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS