{"id":9079,"date":"2023-08-15T10:30:39","date_gmt":"2023-08-15T07:30:39","guid":{"rendered":"https:\/\/oberig-it.com\/?p=9079"},"modified":"2023-08-15T10:35:50","modified_gmt":"2023-08-15T07:35:50","slug":"new-moveit-vulnerability-what-to-do-now-to-protect-your-organization","status":"publish","type":"post","link":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/","title":{"rendered":"New MOVEit Vulnerability: What to Do NOW to Protect Your Organization"},"content":{"rendered":"<p><strong>Overview<\/strong><br \/>\nOn May 31, 2023 Progress Software disclosed a SQL injection vulnerability (CVE-2023-34362) in the MOVEit Transfer that could lead to escalated privileges and potential unauthorized access to the environment. Progress emphasized to its customers that it is extremely important to take immediate action.<\/p>\n<p><strong>Affected versions<\/strong><br \/>\nMOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1)<\/p>\n<p><strong>Details<\/strong><br \/>\nThe SQL injection vulnerability found in the MOVEit Transfer web application allows an unauthenticated attacker to gain access to MOVEit Transfer\u2019s database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database and execute SQL statements that alter or delete database elements. The vendor added that this is exploited in the wild in May and June 2023. Exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions.<\/p>\n<p>The CVSS Base score for this vulnerability is 9.8 and the vector is below:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9071 size-full\" src=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/malyunok-1-fidelis-vrazlyvist-moveit-shho-robyty-dlya-zahystu-vashoyi-organizacziyi.png\" alt=\"\" width=\"1100\" height=\"158\" srcset=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/malyunok-1-fidelis-vrazlyvist-moveit-shho-robyty-dlya-zahystu-vashoyi-organizacziyi.png 1100w, https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/malyunok-1-fidelis-vrazlyvist-moveit-shho-robyty-dlya-zahystu-vashoyi-organizacziyi-300x43.png 300w, https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/malyunok-1-fidelis-vrazlyvist-moveit-shho-robyty-dlya-zahystu-vashoyi-organizacziyi-1024x147.png 1024w, https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/malyunok-1-fidelis-vrazlyvist-moveit-shho-robyty-dlya-zahystu-vashoyi-organizacziyi-768x110.png 768w, https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/malyunok-1-fidelis-vrazlyvist-moveit-shho-robyty-dlya-zahystu-vashoyi-organizacziyi-24x3.png 24w, https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/malyunok-1-fidelis-vrazlyvist-moveit-shho-robyty-dlya-zahystu-vashoyi-organizacziyi-36x5.png 36w, https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/malyunok-1-fidelis-vrazlyvist-moveit-shho-robyty-dlya-zahystu-vashoyi-organizacziyi-48x7.png 48w\" sizes=\"auto, (max-width: 1100px) 100vw, 1100px\" \/><\/p>\n<p>The above CVSS vector indicates that it\u2019s a remotely exploitable network vulnerability. The access complexity is low meaning that an attacker can expect repeatable success when attacking the vulnerable component. There are no special privileges required and therefore an unauthorized attacker without any special access can successfully exploit this issue. The vulnerable system can be exploited without interaction from any user. No one needs to click on open any file or perform any other action. The vulnerability is wormable. And lastly, there is a complete compromise of confidentiality, integrity, and availability of the impacted system.<\/p>\n<p>On June 2, CISA added this vulnerability to the <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Known Exploited Vulnerabilities (KEVs) Catalog<\/span><\/a><\/p>\n<p>On June 7, The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) released a joint <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-158a\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Cybersecurity Advisory<\/span><\/a> to disseminate known CL0P ransomware IOCs and TTPs identified through FBI investigations. According to the report beginning on May 27, 2023, CL0P Ransomware Gang, also known as TA505, began exploiting a previously unknown SQL injection vulnerability which was later disclosed by the vendor on May 31.<\/p>\n<p><strong>Fidelis Cybersecurity Response<\/strong><br \/>\nFidelis Cybersecurity has released detection for various indicators of compromise and indicators of attacks. Customers should patch immediately or deny HTTP\/HTTPs traffic to the MOVEit transfer environment. Customers should review Fidelis alerts and act accordingly to delete any instances of human2.aspx and delete all APP_WEB_[random].dll files. Fidelis\u2019 threat research team is continually tracking this and other emerging and evolving threats to ensure our customers are protected against the latest threats.<\/p>\n<p>Customers should also review various remediation instructions from the <a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Transfer-Critical-Vulnerability-31May2023\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">vendor<\/span><\/a> and the <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-158a\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">CISA<\/span><\/a> advisory. If you are unable to follow the recommended mitigation steps then taking the below security steps to help reduce risk to your MOVEit Transfer environment from unauthorized access. Please see here for <a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Security-Best-Practices-Guide\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">MOVEit Security Best Practices<\/span><\/a>.<\/p>\n<ul>\n<li><strong>Update network firewall rules<\/strong> to only allow connections to the MOVEit Transfer infrastructure from known trusted IP addresses.<\/li>\n<li><strong>Review and remove any unauthorized user accounts<\/strong>. See <a href=\"https:\/\/docs.progress.com\/ru-RU\/bundle\/moveit-transfer-web-admin-help-2022\/page\/Users.html\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Progress MOVEit Users Documentation<\/span><\/a>.<\/li>\n<li><strong>Update remote access<\/strong> policies to only allow inbound connections from known and trusted IP addresses. For more information on restricting remote access, please refer to <a href=\"https:\/\/docs.progress.com\/ru-RU\/bundle\/moveit-transfer-web-admin-help-2022\/page\/System-Remote-Access.html?_ga=2.85172048.857973833.1685632043-529679640.1681734584&amp;_gl=1*gy4jl0*_ga*NTI5Njc5NjQwLjE2ODE3MzQ1ODQ.*_ga_9JSNBCSF54*MTY4NTYzMjA0Mi4yMC4wLjE2ODU2MzIwNTcuNDUuMC4w\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">SysAdmin Remote Access Rules<\/span><\/a> and <a href=\"https:\/\/docs.progress.com\/ru-RU\/bundle\/moveit-transfer-web-admin-help-2022\/page\/Security-Policies-Remote-Access.html\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Security Policies Remote Access<\/span><\/a>.<\/li>\n<li><strong>Allow inbound access only from trusted entities<\/strong> (e.g., using certificate-based access control).<\/li>\n<li><strong>Enable multi-factor authentication<\/strong>. Multi-factor authentication (MFA) protects MOVEit Transfer accounts from unverified users when a user\u2019s account password is lost, stolen, or compromised. To enable MFA, please refer to the <a href=\"https:\/\/docs.progress.com\/ru-RU\/bundle\/moveit-transfer-web-admin-help-2022\/page\/Multi-Factor-Authentication.html\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">MOVEit Transfer Multi-factor Authentication Documentation<\/span><\/a>.<\/li>\n<\/ul>\n<p><strong>Conclusion<\/strong><br \/>\nCVE-2023-34362 has been leveraged by the Cl0p ransomware threat actor to compromise multiple organizations for data exfiltration and other malicious activities. The vulnerability has gained public attention and we expect other threat actors to also leverage this vulnerability. New attempts at exploitation will be accelerated. There is an official patch from the vendor, and we strongly urge customers to patch and review their XDR alerts.<\/p>\n<p>Be sure to subscribe to the Threat Geek blog to stay up to date with the impact of this new vulnerability over the coming weeks.<\/p>\n<p><strong>Source:<\/strong> <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/threat-detection-response\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">New MOVEit Vulnerability: What to Do NOW to Protect Your Organization<\/span><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview On May 31, 2023 Progress Software disclosed a SQL injection vulnerability (CVE-2023-34362) in the MOVEit Transfer that could lead to escalated privileges and potential unauthorized access to the environment. Progress emphasized to its customers that it is extremely important to take immediate action. Affected versions MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), [&hellip;]<\/p>\n","protected":false},"author":850,"featured_media":9069,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[142],"tags":[],"class_list":["post-9079","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>New MOVEit Vulnerability: What to Do NOW to Protect Your Organization \u261d Oberig IT blog<\/title>\n<meta name=\"description\" content=\"New MOVEit Vulnerability: What to Do NOW to Protect Your Organization \u26a1 Oberig IT blog for integrator partners, vendors and end customers\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New MOVEit Vulnerability: What to Do NOW to Protect Your Organization \u261d Oberig IT blog\" \/>\n<meta property=\"og:description\" content=\"New MOVEit Vulnerability: What to Do NOW to Protect Your Organization \u26a1 Oberig IT blog for integrator partners, vendors and end customers\" \/>\n<meta property=\"og:url\" content=\"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/\" \/>\n<meta property=\"og:site_name\" content=\"Oberig IT\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Oberig.disti\" \/>\n<meta property=\"article:published_time\" content=\"2023-08-15T07:30:39+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-08-15T07:35:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/3.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1875\" \/>\n\t<meta property=\"og:image:height\" content=\"625\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Albekova Paula\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Albekova Paula\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"New MOVEit Vulnerability: What to Do NOW to Protect Your Organization \u261d Oberig IT blog","description":"New MOVEit Vulnerability: What to Do NOW to Protect Your Organization \u26a1 Oberig IT blog for integrator partners, vendors and end customers","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/","og_locale":"en_US","og_type":"article","og_title":"New MOVEit Vulnerability: What to Do NOW to Protect Your Organization \u261d Oberig IT blog","og_description":"New MOVEit Vulnerability: What to Do NOW to Protect Your Organization \u26a1 Oberig IT blog for integrator partners, vendors and end customers","og_url":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/","og_site_name":"Oberig IT","article_publisher":"https:\/\/www.facebook.com\/Oberig.disti","article_published_time":"2023-08-15T07:30:39+00:00","article_modified_time":"2023-08-15T07:35:50+00:00","og_image":[{"width":1875,"height":625,"url":"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/3.png","type":"image\/png"}],"author":"Albekova Paula","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Albekova Paula","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/#article","isPartOf":{"@id":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/"},"author":{"name":"Albekova Paula","@id":"https:\/\/oberig-it.com\/en\/#\/schema\/person\/9d804f9c469169d256ca04bc0446793d"},"headline":"New MOVEit Vulnerability: What to Do NOW to Protect Your Organization","datePublished":"2023-08-15T07:30:39+00:00","dateModified":"2023-08-15T07:35:50+00:00","mainEntityOfPage":{"@id":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/"},"wordCount":700,"commentCount":0,"publisher":{"@id":"https:\/\/oberig-it.com\/en\/#organization"},"image":{"@id":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/#primaryimage"},"thumbnailUrl":"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/3.png","articleSection":["Articles"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/","url":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/","name":"New MOVEit Vulnerability: What to Do NOW to Protect Your Organization \u261d Oberig IT blog","isPartOf":{"@id":"https:\/\/oberig-it.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/#primaryimage"},"image":{"@id":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/#primaryimage"},"thumbnailUrl":"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/3.png","datePublished":"2023-08-15T07:30:39+00:00","dateModified":"2023-08-15T07:35:50+00:00","description":"New MOVEit Vulnerability: What to Do NOW to Protect Your Organization \u26a1 Oberig IT blog for integrator partners, vendors and end customers","breadcrumb":{"@id":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/#primaryimage","url":"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/3.png","contentUrl":"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/08\/3.png","width":1875,"height":625},{"@type":"BreadcrumbList","@id":"https:\/\/oberig-it.com\/en\/articles\/new-moveit-vulnerability-what-to-do-now-to-protect-your-organization\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/oberig-it.com\/en\/"},{"@type":"ListItem","position":2,"name":"New MOVEit Vulnerability: What to Do NOW to Protect Your Organization"}]},{"@type":"WebSite","@id":"https:\/\/oberig-it.com\/en\/#website","url":"https:\/\/oberig-it.com\/en\/","name":"Oberig IT","description":"Distribution of complex IT and information security solutions","publisher":{"@id":"https:\/\/oberig-it.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/oberig-it.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/oberig-it.com\/en\/#organization","name":"Oberig IT","url":"https:\/\/oberig-it.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/oberig-it.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/06\/logo-new.svg","contentUrl":"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/06\/logo-new.svg","caption":"Oberig IT"},"image":{"@id":"https:\/\/oberig-it.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Oberig.disti"]},{"@type":"Person","@id":"https:\/\/oberig-it.com\/en\/#\/schema\/person\/9d804f9c469169d256ca04bc0446793d","name":"Albekova Paula","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/oberig-it.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/267b2447d88f2254471421efc84e51964ec66e50c0a67b40f9346d135523b971?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/267b2447d88f2254471421efc84e51964ec66e50c0a67b40f9346d135523b971?s=96&d=mm&r=g","caption":"Albekova Paula"},"sameAs":["https:\/\/oberig-it.com\/"]}]}},"_links":{"self":[{"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/posts\/9079","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/users\/850"}],"replies":[{"embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/comments?post=9079"}],"version-history":[{"count":2,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/posts\/9079\/revisions"}],"predecessor-version":[{"id":9081,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/posts\/9079\/revisions\/9081"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/media\/9069"}],"wp:attachment":[{"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/media?parent=9079"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/categories?post=9079"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/tags?post=9079"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}