HomeSecurityHackers target WhatsUp Gold via public exploit since August

Hackers have been targeting WhatsUp Gold via public exploit since August

Hackers have exploited a public exploit for two critical flaws in Progress Software's WhatsUp Gold network availability and performance monitoring solution.

See also: Adobe fixes zero-day vulnerability in Acrobat Reader (with PoC exploit)

WhatsUp Gold public exploit

The two flaws used in attacks since August 30 are vulnerabilities tracked as CVE-2024-6670 and CVE-2024-6671, which allow for the recovery of encrypted passwords without authentication.

Despite the vendor addressing the security issues more than two weeks ago, many organizations still need to update the software , and threat actors are exploiting this delay.

Progress Software released security updates to address the issues on August 16th and added guidance for identifying potential breaches in a security bulletin on September 10th.

Security researcher Sina Kheirkhah (@SinSinology)discovered the flaws and reported them to the Zero Day Initiative (ZDI) on May 22. On August 30, the researcher published proof-of-concept (PoC) of the exploits.

See also: Russian hackers use exploits created by NSO Group and Intellexa

The researcher explains through the public exploit how to exploit a flaw in user inputs to enter arbitrary passwords in the password field of WhatsUp Gold administrator accounts, thus making them vulnerable to compromise.

Hackers have been targeting WhatsUp Gold via public exploit since August

A report today from cybersecurity firm Trend Micro notes that hackers have begun exploiting the flaws, and based on observations, it appears that the attacks rely on Kheirkhah's PoCs to bypass authentication and access the remote code execution and payload deployment stage.

The security firm's telemetry detected the first signs of active exploitation five hours after the researcher published the PoC exploit code.

Attackers leverage WhatsUp Gold's legitimate Active Monitor PowerShell Script feature to execute multiple PowerShell scripts via NmPoller.exe , retrieved from remote URLs.

See also: Angler Exploit Kit: Reward for information on Belarusian hacker

Exploit code is a program or script that exploits a vulnerability or weakness in a computer system or network. Public exploits can be used by attackers, as in the case of WhatsUp Gold, to gain unauthorized access, compromise data , or cause systems to crash. Understanding how exploits work is critical to security , as it allows experts to identify vulnerabilities and implement appropriate security solutions to protect systems and users.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS