HomeSecurityPoC exploit released for critical vulnerability in Progress WhatsUp Gold

PoC exploit released for critical vulnerability in Progress WhatsUp Gold

A proof-of-concept (PoC) exploit for a critical vulnerability in Progress WhatsUp Gold that allows remote code execution is currently circulating online . As a result, it is essential to install the latest security updates immediately

Progress WhatsUp Gold PoC exploit vulnerability

The vulnerability is tracked as CVE-2024-8785 (CVSS v3.1 score: 9.8/10) and was discovered by Tenable in mid-August 2024. It is found in the NmAPI.exe process since version 2023.1.0 of WhatsUp Gold and prior versions 24.0. 1.

How is the Windows Registry affected?

Upon startup, NmAPI.exe provides a network management API interface for WhatsUp Gold.

See also: Veeam patches vulnerabilities in Service Provider Console (VSPC)

Due to insufficient validation of incoming data, attackers could send specially crafted requests to modify or replace sensitive Windows registry keys that control where WhatsUp Gold configuration files are read from.

“ A remote attacker can invoke the UpdateFailoverRegistryValues ​​function via a netTcpBinding on net.tcp://:9643 ,” Tenable reports

“Through the UpdateFailoverRegistryValues ​​function, the attacker can change an existing registry value or create a new one for any registry path in HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\”.

“Specifically, the attacker can change HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\Network Monitor\WhatsUp Gold\Setup\InstallDir to a UNC path that points to a host controlled by the attacker (e.g. \\share\WhatsUp)“.

See also: Salesforce vulnerabilities allow account takeover

Once the Ipswitch Service Control Manager service is restarted , it will read various configuration files from the remote share controlled by the attacker, which can be used to launch any remote executable file on the vulnerable WhatsUp Gold system.

Exploiting the CVE-2024-8785 vulnerability in Progress WhatsUp Gold does not require authentication, and since the NmAPI.exe service is accessible over the network, the risk is high.

PoC exploit released for critical vulnerability in Progress WhatsUp Gold

Update WhatsUp Gold immediately

System administrators should upgrade Progress WhatsUp Gold to version 24.0.1 as soon as possible. Updates for this vulnerability (and five others) are available as early as September 24, 2024.

See also: Cisco warns of attacks exploiting ASA vulnerability

Extra system protection measures:

  • Regularly check logs and monitor network activity: This can help you detect any suspicious or unauthorized activity on the network.
  • Use two-factor authentication: By requiring an additional authentication method beyond a password, you can increase the security of your accounts.
  • Implement a strong password policy: Encourage employees to use unique and complex passwords for their accounts.
  • Keep software up to date: In addition to security patches, regularly updating software can also address any bugs or vulnerabilities that could potentially be exploited.
  • Conduct regular security training: Educating employees on the latest tactics used by cybercriminals and teaching them how to spot potential threats can significantly reduce the risk of successful attacks.
  • Implement a disaster recovery plan: In the event of a cyberattack, implementing a plan to quickly recover systems and data can minimize downtime and mitigate the impact on operations.
  • Create regular backups: In the event of data loss, taking recent backups can help restore important information and avoid significant disruption to business operations.
  • Use firewalls and network segmentation: Firewalls can prevent unauthorized access , while network segmentation can limit an attacker's ability to move within the system.
  • Stay informed about emerging threats: Staying up to date on the latest cybersecurity news can help organizations stay ahead of potential attacks and take appropriate steps to protect their systems.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS