Hackers have exploited a public exploit for two critical flaws in Progress Software's WhatsUp Gold network availability and performance monitoring solution.
See also: Adobe fixes zero-day vulnerability in Acrobat Reader (with PoC exploit)

The two flaws used in attacks since August 30 are vulnerabilities tracked as CVE-2024-6670 and CVE-2024-6671, which allow for the recovery of encrypted passwords without authentication.
Despite the vendor addressing the security issues more than two weeks ago, many organizations still need to update the software , and threat actors are exploiting this delay.
Progress Software released security updates to address the issues on August 16th and added guidance for identifying potential breaches in a security bulletin on September 10th.
Security researcher Sina Kheirkhah (@SinSinology)discovered the flaws and reported them to the Zero Day Initiative (ZDI) on May 22. On August 30, the researcher published proof-of-concept (PoC) of the exploits.
See also: Russian hackers use exploits created by NSO Group and Intellexa
The researcher explains through the public exploit how to exploit a flaw in user inputs to enter arbitrary passwords in the password field of WhatsUp Gold administrator accounts, thus making them vulnerable to compromise.

A report today from cybersecurity firm Trend Micro notes that hackers have begun exploiting the flaws, and based on observations, it appears that the attacks rely on Kheirkhah's PoCs to bypass authentication and access the remote code execution and payload deployment stage.
The security firm's telemetry detected the first signs of active exploitation five hours after the researcher published the PoC exploit code.
Attackers leverage WhatsUp Gold's legitimate Active Monitor PowerShell Script feature to execute multiple PowerShell scripts via NmPoller.exe , retrieved from remote URLs.
See also: Angler Exploit Kit: Reward for information on Belarusian hacker
Exploit code is a program or script that exploits a vulnerability or weakness in a computer system or network. Public exploits can be used by attackers, as in the case of WhatsUp Gold, to gain unauthorized access, compromise data , or cause systems to crash. Understanding how exploits work is critical to security , as it allows experts to identify vulnerabilities and implement appropriate security solutions to protect systems and users.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
