On September 16th, the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and United States Coast Guard Cyber Command (CGCYBER) released a new joint advisory titled – Alert (AA21-259A) APT Actors Exploiting Newly Identified Vulnerability in ManageEngine ADSelfService Plus. Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to a REST API authentication bypass, which ultimately allows for remote code execution. The vulnerability has been assigned CVE-2021-40539.What Are the Technical Details of the Vulnerability?An authentication bypass vulnerability exists in Zoho ManageEngine ADSelfService Plus version 6113 and prior. Remote code execution is possible via affected REST API URL(s) that could allow for remote code execution. Successful exploitation of the vulnerability allows an attacker to place webshells within the victim environment. Once inside the victim environment, an adversary can conduct the following – Lateral movement, compromising administrator credentials, post exploitation, and exfiltrating registry hives and Active Directory files from a domain controller.Is this Being Exploited in the Wild?Yes. According to US-CERT, this is limited to targeted attacks by a sophisticated unnamed APT group.What Verticals are Being Targeted?According to the US-CERT alert, the following list of verticals have been observed to be targeted – academic institutions, defense contractors, and critical infrastructure entities in multiple industry sectors including transportation, IT, manufacturing, communications, logistics, and finance. What is the CVSS score?9.8 CRITICALHas the Vendor Issued a Patch?Yes, patches were released on September 6th, 2021 by the vendor. Please refer to the APPENDIX “ADSelfService Plus 6114 Security Fix Release” for details.What is the Status of Coverage? FortiGuard Labs provides the following IPS signature for CVE-2021-40539:Zoho.ManageEngine.ADSelfService.Plus.Authentication.BypassAny Mitigation and or Workarounds?It is strongly recommended to update to ADSelfService Plus build 6114. This update is located on the vendor homepage “ADSelfService Plus 6114 Security Fix Release” within the APPENDIX. It is also highly suggested to keep all affected devices from being publicly accessible or being placed behind a physical security appliance/firewall, such as a FortiGate. For further mitigation and workarounds, please refer to the US-CERT Alert and the Zoho Advisory in the APPENDIX.
More Stories
chromium-117.0.5938.132-2.fc39
FEDORA-2023-c890266d3f Packages in this update: chromium-117.0.5938.132-2.fc39 Update description: update to 117.0.5938.132. Fixes following security issues: CVE-2023-5129 CVE-2023-5186 Update to 117.0.5938.92....
chromium-117.0.5938.132-2.fc38
FEDORA-2023-d66a01ad4f Packages in this update: chromium-117.0.5938.132-2.fc38 Update description: update to 117.0.5938.132. Fixes following security issues: CVE-2023-5129 CVE-2023-5186 Read More
chromium-117.0.5938.132-1.el7
FEDORA-EPEL-2023-edc9c74369 Packages in this update: chromium-117.0.5938.132-1.el7 Update description: update to 117.0.5938.132. Fixes following security issues: CVE-2023-5129 CVE-2023-5186 Update to 117.0.5938.92....
chromium-117.0.5938.132-1.el8
FEDORA-EPEL-2023-8f3e1b6f78 Packages in this update: chromium-117.0.5938.132-1.el8 Update description: update to 117.0.5938.132. Fixes following security issues: CVE-2023-5129 CVE-2023-5186 Update to 117.0.5938.92....
chromium-117.0.5938.132-1.fc37
FEDORA-2023-0cd03c3746 Packages in this update: chromium-117.0.5938.132-1.fc37 Update description: update to 117.0.5938.132. Fixes following security issues: CVE-2023-5129 CVE-2023-5186 Read More
chromium-117.0.5938.132-1.el9
FEDORA-EPEL-2023-cca1f87440 Packages in this update: chromium-117.0.5938.132-1.el9 Update description: update to 117.0.5938.132. Fixes following security issues: CVE-2023-5129 CVE-2023-5186 Update to 117.0.5938.92....