Gladinet , the company behind the CentreStack platform , has released a security update to fix a serious vulnerability exploited by malicious attackers. The flaw, known as unauthenticated local file inclusion , allows attackers to obtain the machine key and execute code remotely via a ViewState deserialization issue .
See also: Active vulnerability exploitation in Gladinet and TrioFox

The vulnerability was first discovered by security researchers who observed unusual activity on systems running CentreStack. Unauthenticated local file inclusion is a type of flaw that allows an attacker to insert files from the server's local system without requiring authentication. This can lead to the disclosure of sensitive information, such as the machineKey, which is critical to the security of the application.
Gladinet responded promptly to the bug report and worked closely with the security community to develop and distribute an update that fixes the issue. This update is available to all CentreStack users and the company strongly recommends its immediate implementation to prevent potential attacks.
See also: Juniper Networks patches critical vulnerabilities in Junos Space

The flaw exploits a deserialization issue in ViewState, a technology used to maintain state in ASP.NET between HTTP requests. Deserialization is the process of converting data from a stored state format to a format that can be used by the program. When deserialization is not done in a secure manner, it could allow attackers to execute arbitrary code on the system.
Gladinet has also issued guidelines to strengthen the security of systems using CentreStack, suggesting measures such as using strong passwords, regularly updating software, and monitoring systems for unusual activity. The company emphasizes the importance of ongoing security education for users and system administrators to prevent future attacks.
This flaw highlights the importance of regularly updating systems and collaboration between software companies and the security community to address ever-evolving threats. Gladinet is committed to continuing to work on improving the security of its products and providing its customers with the best possible solutions to protect their data.
See also: GitHub Copilot: Vulnerability allows code extraction from private repositories

CentreStack users are encouraged to contact Gladinet customer support for more information on the update and recommended security practices. The company remains committed to providing secure and reliable solutions for its customers' needs.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
