A proof-of-concept (PoC) exploit for a critical vulnerability in Progress WhatsUp Gold that allows remote code execution is currently circulating online . As a result, it is essential to install the latest security updates immediately

The vulnerability is tracked as CVE-2024-8785 (CVSS v3.1 score: 9.8/10) and was discovered by Tenable in mid-August 2024. It is found in the NmAPI.exe process since version 2023.1.0 of WhatsUp Gold and prior versions 24.0. 1.
How is the Windows Registry affected?
Upon startup, NmAPI.exe provides a network management API interface for WhatsUp Gold.
See also: Veeam patches vulnerabilities in Service Provider Console (VSPC)
Due to insufficient validation of incoming data, attackers could send specially crafted requests to modify or replace sensitive Windows registry keys that control where WhatsUp Gold configuration files are read from.
“ A remote attacker can invoke the UpdateFailoverRegistryValues function via a netTcpBinding on net.tcp://:9643 ,” Tenable reports
“Through the UpdateFailoverRegistryValues function, the attacker can change an existing registry value or create a new one for any registry path in HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\”.
“Specifically, the attacker can change HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\Network Monitor\WhatsUp Gold\Setup\InstallDir to a UNC path that points to a host controlled by the attacker (e.g. \\share\WhatsUp)“.
See also: Salesforce vulnerabilities allow account takeover
Once the Ipswitch Service Control Manager service is restarted , it will read various configuration files from the remote share controlled by the attacker, which can be used to launch any remote executable file on the vulnerable WhatsUp Gold system.
Exploiting the CVE-2024-8785 vulnerability in Progress WhatsUp Gold does not require authentication, and since the NmAPI.exe service is accessible over the network, the risk is high.

Update WhatsUp Gold immediately
System administrators should upgrade Progress WhatsUp Gold to version 24.0.1 as soon as possible. Updates for this vulnerability (and five others) are available as early as September 24, 2024.
See also: Cisco warns of attacks exploiting ASA vulnerability
Extra system protection measures:
- Regularly check logs and monitor network activity: This can help you detect any suspicious or unauthorized activity on the network.
- Use two-factor authentication: By requiring an additional authentication method beyond a password, you can increase the security of your accounts.
- Implement a strong password policy: Encourage employees to use unique and complex passwords for their accounts.
- Use strong encryption: Encrypting sensitive data can prevent it from being easily accessed by unauthorized parties.
- Keep software up to date: In addition to security patches, regularly updating software can also address any bugs or vulnerabilities that could potentially be exploited.
- Conduct regular security training: Educating employees on the latest tactics used by cybercriminals and teaching them how to spot potential threats can significantly reduce the risk of successful attacks.
- Implement a disaster recovery plan: In the event of a cyberattack, implementing a plan to quickly recover systems and data can minimize downtime and mitigate the impact on operations.
- Create regular backups: In the event of data loss, taking recent backups can help restore important information and avoid significant disruption to business operations.
- Use firewalls and network segmentation: Firewalls can prevent unauthorized access , while network segmentation can limit an attacker's ability to move within the system.
- Stay informed about emerging threats: Staying up to date on the latest cybersecurity news can help organizations stay ahead of potential attacks and take appropriate steps to protect their systems.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
