zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Reports of Active Exploitation of MOVEit Transfer SQL Zero-Day Vulnerability

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Reports of Active Exploitation of MOVEit Transfer SQL Zero-Day Vulnerability

Product Serial: F-2023-06-02b

TLP:CLEAR

In this flash report, ZeroFox researchers provide an overview of a zero-day vulnerability that was disclosed in MOVEit Transfer, a secure managed file transfer software developed by Progress Software Corporation. All MOVEit Transfer versions are affected by this vulnerability, with security patches released for five supported versions.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download View the full report here.

Key Findings

  • A zero-day vulnerability was identified in MOVEit Transfer, a secure managed file transfer software, with reports stating it is being actively exploited in attacks. All MOVEit Transfer versions are affected by this vulnerability.
  • The zero-day vulnerability is reported to be a SQL injection vulnerability that can enable threat actors to gain unauthorized access to the environment, escalate privileges, make unauthorized changes to the database, and exfiltrate data from victims. Threat actors have devised a method to leverage this vulnerability to execute arbitrary code.
  • ZeroFox Intelligence has not observed significant chatter about this vulnerability on the Deep and Dark Web (DDW). A working Proof-of-Concept (POC) has not been released publicly.
  • Customers are advised to implement security patches to supported versions as quickly as possible.

Tags: tlp:clear,  vulnerability/exploit,  technology,  global