HomeSecurityZero-day in Sitecore configuration actively exploited

Zero-day in Sitecore configuration is actively exploited

ASP.NET machine key in old development guides for Sitecore products is being exploited by hackers to perform ViewState code injection attacks that compromise servers. According to Google's Mandiant Threat Defense team , after the initial exploit, attackers deploy tools to escalate privileges, add new users (including administrators), create remote access tunnels, and dump credentials that allow them to perform lateral movement to other hosts on the network.

See also: Android Security Update – Fixing zero-day vulnerabilities

Sitecore zero-day

“The attacker’s deep understanding of the compromised product and the exploited vulnerability was evident in their progression from initial server compromise to escalation of privileges,” the Mandiant team said in report . Instances of Sitecore Experience Manager (XM), Experience Platform (XP) , and Experience Commerce (XC) deployed in multi-instance mode with customer-managed static Machine keys using the key sample in question are affected by this vulnerability, tracked as CVE-2025-53690. Instances of Sitecore Managed Cloud Standard with Containers deployed in multi-instance mode could also be affected, according to Sitecore’s announcement.

In the ASP.NET programming language, ViewState is a method of preserving the state of web pages during web form submissions. This information is stored in a hidden HTML field named __VIEWSTATE and can be signed and encrypted with keys, called ValidationKey and DecryptionKey, stored in the application's configuration file. If these keys are stolen or leaked, attackers can use them to create malicious ViewState payloads within POST requests that the server will decrypt, validate, and execute by loading them into the memory of its worker process.

These attacks are known as ViewState code injection or ViewState deserialization, and they are not new. Microsoft warned in December that it had seen attacks in the field exploiting this technique and had identified over 3,000 publicly disclosed Machine keys that could be abused. The attack investigated by Mandiant exploited one such key that was included as a sample in deployment guidelines dating back to 2017 for Sitecore XP 9.0 or earlier and Active Directory 1.4.

Newer Sitecore deployments generate unique keys for each installation, but users who deployed their instances using the old deployment guides and used the sample keys should now check their installations for signs of compromise. The malicious actor behind the incident investigated by Mandiant exploited CVE-2025-53690 to inject a .NET assembly called Information.dll via ViewState.

See also: Hackers leverage Hexstrike-AI for Zero Day exploit

Zero-day in Sitecore configuration is actively exploited
Zero-day in Sitecore configuration is actively exploited

This information gathering tool, which Mandiant tracks as WEEPSTEEL, is similar to the backdoor GhostContainer. In the context of the attack, WEEPSTEEL was used to gather information about the system and users and give the attackers the NETWORK SERVICE on the system, which is the account used by the Microsoft IIS. This allowed them to extract configuration files from the application that contained sensitive information. The attackers then downloaded additional tools that were previously placed in the Music and Videos directories. These tools included the 7za.exe, a SOCKS v5 that Mandiant tracks as EARTHWORM, VBS scripts containing malicious commands, and various privilege escalation tools.

Privilege escalation tools allowed attackers to gain SYSTEM privileges and create additional accounts on the system, including administrative accounts named asp$ and sawadmin. Additional tools developed and used with these accounts included a tool named DWAGENT and a user token theft tool named GoToken.exe. The attackers also used their access to dump the SYSTEM and SAM registry hives to extract password hashes for all local users configured on the system.

This information was used to initiate lateral movement via Remote Desktop Protocol (RDP). The SHARPHOUND tool, which is part of the BloodHound Active Directory analysis framework, was also deployed. The attackers were able to jump to other systems on the network using RDP and the account credentials they collected. The EARTHWORM tunneling tool was also deployed to these systems.

See also: Critical Citrix Zero-Day Exposes Global Organizations

Zero-day in Sitecore configuration is actively exploited
Zero-day in Sitecore configuration is actively exploited

Sitecore users who believe their deployments may be affected should immediately examine their environments for signs of compromise and malware. Mandiant’s report includes indicators of compromise that can be used to generate detection signatures. Users should also rotate machine keys within their web.config files and ensure that any elements in their configuration files are encrypted. The web.config file should be configured to be accessible to application administrators, and machine keys should be rotated automatically in accordance with Microsoft’s ASP.NET ViewState security guidelines.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS