Facebook Twitter Instagram
    • Privacy Policy
    • Contact Us
    Facebook Twitter Instagram Pinterest Vimeo
    AI Home SecurityAI Home Security
    • Home
    • Home Security
    • Cyber Security
    • Biometric Technology
    Contact
    AI Home SecurityAI Home Security
    Cyber Security

    Zoho ManageEngine PoC Exploit to be Released Soon

    justmattgBy justmattgJanuary 22, 2023No Comments3 Mins Read

    [ad_1]

    Jan 17, 2023Ravie LakshmananCyber Threat / Vulnerability

    Zoho ManageEngine PoC Exploit

    Users of Zoho ManageEngine are being urged to patch their instances against a critical security vulnerability ahead of the release of a proof-of-concept (PoC) exploit code.

    The issue in question is CVE-2022-47966, an unauthenticated remote code execution vulnerability affecting several products due to the use of an outdated third-party dependency, Apache Santuario.

    “This vulnerability allows an unauthenticated adversary to execute arbitrary code,” Zoho warned in an advisory issued late last year, noting that it affects all ManageEngine setups that have the SAML single sign-on (SSO) feature enabled, or had it enabled in the past.

    Horizon3.ai has now released Indicators of Compromise (IOCs) associated with the flaw, stating that it was able to successfully reproduce the exploit against ManageEngine ServiceDesk Plus and ManageEngine Endpoint Central products.

    “The vulnerability is easy to exploit and a good candidate for attackers to ‘spray and pray’ across the internet,” researcher James Horseman said. “This vulnerability allows for remote code execution as NT AUTHORITYSYSTEM, essentially giving an attacker complete control over the system.”

    An attacker in possession of such elevated privileges could weaponize it to steal credentials with the goal of conducting lateral movement, the San Francisco-headquartered firm said, adding the threat actor will need to send a specially crafted SAML request to trigger the exploit.

    Horizon3.ai further called attention to the fact that there are more than 1,000 instances of ManageEngine products exposed to the internet with SAML currently enabled, potentially turning them into lucrative targets.

    It’s not uncommon for hackers to exploit awareness of a major vulnerability for malicious campaigns. It’s therefore essential that the fixes are installed as soon as possible irrespective of the SAML configuration.

    Update: PoC Exploit Released

    Horizon3.ai has officially released an exploit for CVE-2022-47966, a critical security flaw in several Zoho ManageEngine products that allows an adversary to gain remote code execution by issuing a HTTP POST request containing a malicious SAML response.

    Cybersecurity company Rapid7 disclosed that it’s “responding to various compromises arising from the exploitation of CVE-2022-47966” since at least January 17, 2023, with the threat actors weaponizing the flaw to drop PowerShell scripts to disable Microsoft Defender Antivirus real-time protections and download additional remote access tools.

    “Organizations using any of the affected products […] should update immediately and review unpatched systems for signs of compromise, as exploit code is publicly available and exploitation has already begun,” Rapid7 researcher Glenn Thorpe said.

    Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



    [ad_2]

    Source link

    Previous ArticleCISA Warns of Flaws in Siemens, GE Digital, and Contec Industrial Control Systems
    Next Article 10 Home Upgrades To Make If You’re Over 65 — Best Life
    justmattg
    • Website

    Related Posts

    Cyber Security

    Name That Toon: Last Line of Defense

    April 16, 2024
    Cyber Security

    OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

    April 16, 2024
    Cyber Security

    Middle East Cyber Ops Intensify, With Israel the Main Target

    April 16, 2024
    Add A Comment

    Leave A Reply Cancel Reply

    Facebook Twitter Instagram Pinterest
    • Privacy Policy
    • Contact Us
    AI Home Security © 2025 All rights reserved | Designed By ESmartsSolution

    Type above and press Enter to search. Press Esc to cancel.

    ↑