HomeSecurityMOVEit Transfer: Critical vulnerability exploited by hackers

MOVEit Transfer: Critical vulnerability exploited by hackers

Hackers are already trying to exploit a critical vulnerability in Progress' MOVEit Transfer software. The vulnerability allows bypass authentication and was disclosed by the company the day before yesterday.

MOVEit Transfer vulnerability

MOVEit Transfer is a popular software used in corporate environments to securely transfer files between business partners and customers.

The vulnerability, which was discovered, is tracked as CVE-2024-5806 and allows attackers to bypass the authentication process in the Secure File Transfer Protocol (SFTP) module, which is responsible for file transfer operations over SSH.

See also: Apple fixes AirPods Bluetooth vulnerability

An attacker who exploited this vulnerability could access sensitive data stored on the MOVEit Transfer server, upload, download, delete, or modify files, or intercept or disrupt file transfers.

Threat monitoring platform Shadowserver Foundation saw attempts to exploit the vulnerability shortly after Progress's bulletin was published.

Censys says there are approximately 2,700 MOVEit Transfer instances exposed on the Internet (mainly in the US, UK, Germany, Canada and the Netherlands).

ShadowServer's report of exploit attempts comes after watchTowr published technical details about exploiting the vulnerability. watchTowr also provided a technical analysis of how attackers can manipulate SSH public key paths to force the server to authenticate using paths controlled by the attackers, potentially exposing Net-NTLMv2 hashes.

See also: Botnet exploits vulnerability in Zyxel NAS devices

The PoC exploit and the information made public will make hackers' jobs much easier.

Progress MOVEit Transfer: CVE-2024-5806

The company says that the CVE-2024-5806 vulnerability affects the following product versions:

  • 2023.0.0 before 2023.0.11
  • 2023.1.0 before 2023.1.6
  • 2024.0.0 before 2024.0.2

The fixes were made available in MOVEit Transfer versions 2023.0.11, 2023.1.6, and 2024.0.2.

Customers without a current maintenance agreement should immediately contact the Renewals team or a Progress partner to resolve the issue.

MOVEit Cloud customers do not need to take any action, as the updates have already been applied automatically.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

MOVEit Transfer: Critical vulnerability exploited by hackers

Progress also said it discovered a separate vulnerability in a third-party component used in MOVEit Transfer, which increases the risks associated with the CVE-2024-5806 vulnerability.

To mitigate the risk associated with this bug, it is recommended that system administrators block access Remote Desktop Protocol (RDP) to MOVEit Transfer servers and restrict outbound connections to known/trusted endpoints.

See also: GrimResource: New attack uses MSC files and Windows XSS vulnerability

The vulnerabilities above serve as a reminder of the ongoing threat posed by cyber, and show that organizations must remain vigilant in protecting their systems. By staying up-to-date on the latest security vulnerabilities and addressing them early, we can help prevent potential attacks and keep our systems secure. So let’s continue to prioritize cybersecurity and take proactive steps to stay one step ahead of threats. The next time a critical vulnerability is discovered, don’t wait for hackers to exploit it – take action now to protect your organization’s data.

 The Internet is constantly evolving, making it vital for organizations to constantly monitor their systems for potential security. Regularly updating software and implementing strong security measures are important steps to mitigate any threats.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS