HomeSecurityHackers exploit KerioControl flaw to steal credentials

Hackers exploit KerioControl flaw to steal credentials

Hackers are attempting to exploit CVE-2024-52875 , a critical CRLF injection flaw that allows 1-click remote code execution (RCE) attacks on the GFI KerioControl firewall product .

See also: RCE vulnerability in Kerio Control allows root access to firewall

KerioControl defect

KerioControl is a network security solution designed for small and medium-sized businesses that combines firewall, VPN, bandwidth management, reporting and monitoring, traffic filtering, AV protection, and intrusion prevention.

On December 16, 2024, security researcher Egidio Romano (EgiX) published a detailed description of CVE-2024-52875, showing how a seemingly low-severity HTTP response splitting issue could escalate to a 1-click RCE.

The flaw, which affects KerioControl versions 9.2.5 to 9.4.5, is due to improper sanitization of line feed (LF) characters in the "dest" parameter, allowing manipulation of the HTTP header and response via injected payloads. Malicious JavaScript injected into the responses is executed in the victim's browser, leading to cookie or CSRF token extraction.

See also: WordPress: Critical vulnerabilities in Spam protection, Anti-Spam, FireWall plugin

An attacker could use the CSRF token of a authenticated admin user to upload a malicious .IMG file containing a root-level shell script, leveraging Kerio's upgrade feature, which opens a reverse shell for the attacker.

Hackers exploit KerioControl flaw to steal credentials

Yesterday, threat scanning platform Greynoise detected exploit attempts targeting CVE-2024-52875 from four distinct IP addresses, likely using the PoC exploit code presented by Romano. The activity is marked as “malicious” by the threat monitoring platform, indicating that the exploit are attributed to threat actors rather than researchers investigating systems.

If a patch for the flaw is not currently possible, administrators should restrict access to the KerioControl web management interface to trusted IP addresses and disable public access to the '/admin' and '/noauth' via firewall rules.

See also: Zyxel firewall vulnerability exploited in Ransomware attacks

A firewall flaw refers to a vulnerability or weakness in the design, configuration, or implementation of a firewall that could be exploited by attackers. Such flaws could allow unauthorized access to networks, bypass security restrictions, or leak sensitive information. Common causes of firewall flaws include outdated software, misconfigurations, or failure to apply necessary patches. Identifying and addressing these weaknesses is crucial to maintaining strong network security and preventing potential cyber threats.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS