{"id":8940,"date":"2023-06-05T09:30:31","date_gmt":"2023-06-05T03:30:31","guid":{"rendered":"https:\/\/www.reveantivirus.com\/blog\/?p=8940"},"modified":"2023-06-06T09:15:13","modified_gmt":"2023-06-06T03:15:13","slug":"moveit-transfers-zero-day-vulnerability","status":"publish","type":"post","link":"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability","title":{"rendered":"Hackers Target MOVEit Transfer\u2019s Zero-Day Vulnerability, Emergency Patch Deployed"},"content":{"rendered":"<p><span style=\"font-weight: 400;\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-8943\" src=\"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2023\/06\/blog.jpg\" alt=\"\" width=\"1728\" height=\"972\" \/>Cybersecurity experts are raising a flag about a potential zero-day exploit vulnerability of a popular file transfer tool which could result in a huge security disaster as thousands of organizations actively use it. MOVEit Transfer managed file transfer (MFT) is a popular file transfer tool used by thousands of organizations across the world. It allows users to share large files and datasets over the internet safely and effortlessly.<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">Details on The Threat<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Researchers found a glitch or backdoor, a vulnerability to this famous corporate file transfer tool that could hand over potential unauthorized access and\/or escalated privileges to any intruder. And the threat is actually<\/span><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Transfer-Critical-Vulnerability-31May2023\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\"> confirmed by Progress Softwares<\/span><\/a><span style=\"font-weight: 400;\">, the parent company owning Ipswitch, developer of MOVEit Transfer.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This exploit is possible due to a SQL injection vulnerability present in the MOVEit Transfer web application. Using the weakness an intruder could get information regarding the structure and contents of the database any of the widely used database engines including MySQL, Microsoft SQL Server, or Azure SQL is used. To some extent, the vulnerability even allows a hacker to execute SQL statements that can alter or delete database elements.<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">A Real Threat Or Just Another Hoax?<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Below quotation is directly from the mother company that owns the affected software &#8211;\u00a0<\/span><\/p>\n<blockquote><p><span style=\"font-weight: 400;\">\u201c<\/span><i><span style=\"font-weight: 400;\">Progress has discovered a vulnerability in MOVEit Transfer that could lead to escalated privileges and potential unauthorized access to the environment. If you are a MOVEit Transfer customer, it is extremely important that you take immediate action as noted below in order to help protect your MOVEit Transfer environment, while our team produces a patch<\/span><\/i><span style=\"font-weight: 400;\">\u201d<\/span><\/p><\/blockquote>\n<p><span style=\"font-weight: 400;\">If this statement alone is not enough, let\u2019s see what other experts are saying about this.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">America\u2019s Cyber Defence Agency <\/span><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/06\/01\/progress-software-releases-security-advisory-moveit-transfer\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">CISA has advised<\/span><\/a><span style=\"font-weight: 400;\"> all users and organizations to review their current status of MOVEit Transfer Advisory and follow all the mitigation and security checks advised by the developer company.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In addition, this vulnerability also reaches out to the cloud platform users of MOVEit Transfer. Apart from the large user base in the healthcare industry and several big financial institutions, there is at least one incident where the U.S. Department of Homeland Security is somehow connected, <\/span><a href=\"https:\/\/cyberplace.social\/@GossiTheDog\/110469935523717355\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">suggested security researcher Kevin Beaumont<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-8945\" src=\"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2023\/06\/blog1.jpg\" alt=\"\" width=\"1824\" height=\"1026\" \/><\/p>\n<h3><span style=\"font-weight: 400;\">Is There Any Remedy?<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">The <\/span><a href=\"https:\/\/www.reveantivirus.com\/blog\/en\/zero-day-threat\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">nature of zero-day vulnerability<\/span><\/a><span style=\"font-weight: 400;\"> is that they are not preventable. However, security experts are continuously working to mitigate any potential disaster. There are also emergency mitigation steps recommended by the vendor itself, progress software, and almost everyone is suggesting to follow the process for the best available safety to the vulnerability. Let\u2019s take a look at it.\u00a0<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">Suggested Mitigation Steps<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Progress Software suggests implying below steps ASAP to prevent any further exploitation<\/span><\/p>\n<p><b>Disabling all HTTP and HTTPs traffic<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Modify the firewall rules to deny HTTP and HTTPs traffic until the patch is applied<\/span><\/p>\n<p><b>Review, Delete and Reset<\/b><\/p>\n<p><b>Review<\/b><span style=\"font-weight: 400;\"> logs for unexpected downloads of files from unknown IPs or large numbers of files downloaded. Look for any unauthorized files or user accounts, specifically <\/span><b>delete<\/b><span style=\"font-weight: 400;\"> any instances of the human2.aspx and .cmdline script files. <\/span><b>Reset<\/b><span style=\"font-weight: 400;\"> service account credentials for affected systems<\/span><\/p>\n<p><b>Patch Applying<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Patches for various MOVEit Transfer versions are made available by the vendor, in this step apply the patch. If the version is outdated, immediately update the software version.<\/span><\/p>\n<p><b>Enabling HTTP and HTTPs traffic<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In this step, re-enable the inbound traffic<\/span><\/p>\n<p><b>Further Verification<\/b><\/p>\n<p><span style=\"font-weight: 400;\">To successfully verify that no unauthorized accounts are there, follow the <\/span><i><span style=\"font-weight: 400;\">Review, Delete and Reset <\/span><\/i><span style=\"font-weight: 400;\">step again. If no further issue is found, continue to the next step, if found, reset the service account residential again.<\/span><\/p>\n<p><b>Always Keep Monitoring<\/b><\/p>\n<p><span style=\"font-weight: 400;\">It\u2019s always a best practice to keep monitoring the whole scenario. Further details about the mitigation steps could be found <\/span><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Transfer-Critical-Vulnerability-31May2023\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">here<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">For the user\u2019s safety. It\u2019s always recommended to\u00a0 follow the mitigation steps, apply the necessary patches &amp; updates, and always stay wary for any suspicious activity.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Potential zero-day exploit vulnerability of a popular file transfer tool could result in huge cybersecurity blunder to thousands of active users<\/p>\n","protected":false},"author":27,"featured_media":8945,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[94,203,93,317,476],"tags":[218,457,106,127],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v18.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Potential zero-day exploit vulnerability of a popular file transfer tool could result in huge cybersecurity blunder to thousands of active users\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackers Target MOVEit Transfer\u2019s Zero-Day Vulnerability, Emergency Patch Deployed\" \/>\n<meta property=\"og:description\" content=\"Potential zero-day exploit vulnerability of a popular file transfer tool could result in huge cybersecurity blunder to thousands of active users\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability\" \/>\n<meta property=\"og:site_name\" content=\"REVE Antivirus\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/REVE-Antivirus-733117470104716\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-05T03:30:31+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-06-06T03:15:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2023\/06\/blog1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1824\" \/>\n\t<meta property=\"og:image:height\" content=\"1026\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<meta name=\"twitter:creator\" content=\"@REVEAntivirus\" \/>\n<meta name=\"twitter:site\" content=\"@REVEAntivirus\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Shahriar Rahman\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/#website\",\"url\":\"https:\/\/www.reveantivirus.com\/blog\/\",\"name\":\"REVE Antivirus\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.reveantivirus.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2023\/06\/blog1.jpg\",\"contentUrl\":\"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2023\/06\/blog1.jpg\",\"width\":1824,\"height\":1026},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability#webpage\",\"url\":\"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability\",\"name\":\"Hackers Target MOVEit Transfer\u2019s Zero-Day Vulnerability, Emergency Patch Deployed\",\"isPartOf\":{\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability#primaryimage\"},\"datePublished\":\"2023-06-05T03:30:31+00:00\",\"dateModified\":\"2023-06-06T03:15:13+00:00\",\"author\":{\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/#\/schema\/person\/fb7225359a07ccc0a80efa9d3e0fa901\"},\"description\":\"Potential zero-day exploit vulnerability of a popular file transfer tool could result in huge cybersecurity blunder to thousands of active users\",\"breadcrumb\":{\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.reveantivirus.com\/blog\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hackers Target MOVEit Transfer\u2019s Zero-Day Vulnerability, Emergency Patch Deployed\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/#\/schema\/person\/fb7225359a07ccc0a80efa9d3e0fa901\",\"name\":\"Shahriar Rahman\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/9373b9bc56eedfacacadaf6316294d64?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/9373b9bc56eedfacacadaf6316294d64?s=96&d=mm&r=g\",\"caption\":\"Shahriar Rahman\"},\"description\":\"Shahriar is a cybersecurity enthusiastic, computer geek and keen blogger. Writing in various niches for the last five years. Working towards making the internet a safer place for everyone.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/shahriar019\/\"],\"url\":\"https:\/\/www.reveantivirus.com\/blog\/author\/shahriar\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Potential zero-day exploit vulnerability of a popular file transfer tool could result in huge cybersecurity blunder to thousands of active users","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability","og_locale":"en_US","og_type":"article","og_title":"Hackers Target MOVEit Transfer\u2019s Zero-Day Vulnerability, Emergency Patch Deployed","og_description":"Potential zero-day exploit vulnerability of a popular file transfer tool could result in huge cybersecurity blunder to thousands of active users","og_url":"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability","og_site_name":"REVE Antivirus","article_publisher":"https:\/\/www.facebook.com\/REVE-Antivirus-733117470104716","article_published_time":"2023-06-05T03:30:31+00:00","article_modified_time":"2023-06-06T03:15:13+00:00","og_image":[{"width":1824,"height":1026,"url":"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2023\/06\/blog1.jpg","type":"image\/jpeg"}],"twitter_card":"summary","twitter_creator":"@REVEAntivirus","twitter_site":"@REVEAntivirus","twitter_misc":{"Written by":"Shahriar Rahman","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/www.reveantivirus.com\/blog\/#website","url":"https:\/\/www.reveantivirus.com\/blog\/","name":"REVE Antivirus","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.reveantivirus.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability#primaryimage","inLanguage":"en-US","url":"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2023\/06\/blog1.jpg","contentUrl":"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2023\/06\/blog1.jpg","width":1824,"height":1026},{"@type":"WebPage","@id":"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability#webpage","url":"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability","name":"Hackers Target MOVEit Transfer\u2019s Zero-Day Vulnerability, Emergency Patch Deployed","isPartOf":{"@id":"https:\/\/www.reveantivirus.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability#primaryimage"},"datePublished":"2023-06-05T03:30:31+00:00","dateModified":"2023-06-06T03:15:13+00:00","author":{"@id":"https:\/\/www.reveantivirus.com\/blog\/#\/schema\/person\/fb7225359a07ccc0a80efa9d3e0fa901"},"description":"Potential zero-day exploit vulnerability of a popular file transfer tool could result in huge cybersecurity blunder to thousands of active users","breadcrumb":{"@id":"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.reveantivirus.com\/blog\/en\/moveit-transfers-zero-day-vulnerability#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.reveantivirus.com\/blog"},{"@type":"ListItem","position":2,"name":"Hackers Target MOVEit Transfer\u2019s Zero-Day Vulnerability, Emergency Patch Deployed"}]},{"@type":"Person","@id":"https:\/\/www.reveantivirus.com\/blog\/#\/schema\/person\/fb7225359a07ccc0a80efa9d3e0fa901","name":"Shahriar Rahman","image":{"@type":"ImageObject","@id":"https:\/\/www.reveantivirus.com\/blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/9373b9bc56eedfacacadaf6316294d64?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9373b9bc56eedfacacadaf6316294d64?s=96&d=mm&r=g","caption":"Shahriar Rahman"},"description":"Shahriar is a cybersecurity enthusiastic, computer geek and keen blogger. Writing in various niches for the last five years. Working towards making the internet a safer place for everyone.","sameAs":["https:\/\/www.linkedin.com\/in\/shahriar019\/"],"url":"https:\/\/www.reveantivirus.com\/blog\/author\/shahriar"}]}},"_links":{"self":[{"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/posts\/8940"}],"collection":[{"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/comments?post=8940"}],"version-history":[{"count":4,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/posts\/8940\/revisions"}],"predecessor-version":[{"id":8944,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/posts\/8940\/revisions\/8944"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/media\/8945"}],"wp:attachment":[{"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/media?parent=8940"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/categories?post=8940"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/tags?post=8940"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}