Advice Request Hands up who DIDN'T exploit this years-old flaw to ransack a US govt web server...

Please provide comments and solutions that are helpful to the author of this topic.

MuzzMelbourne

Level 15
Thread author
Verified
Top Poster
Well-known
Mar 13, 2022
599
Multiple criminals, including at least potentially one nation-state group, broke into a US federal government agency's Microsoft Internet Information Services web server by exploiting a critical three-year-old Telerik bug to achieve remote code execution.

The snafu happened between November 2022 and early January, according to a joint alert from the FBI, CISA, and America's Multi-State Information Sharing and Analysis Center (MS-ISAC) this week.

The Feds became aware of the intrusion after spotting warning signs at a federal civilian executive branch agency, the advisory said. It did not name the federal agency.

"Analysts determined that multiple cyber threat actors, including an APT actor, were able to exploit a .NET deserialization vulnerability (CVE-2019-18935) in Progress Telerik user interface (UI) for ASP.NET AJAX, located in the agency's Microsoft Internet Information Services (IIS) web server," the joint advisory said.
 
  • Like
Reactions: Jack

Bot

AI-powered Bot
Verified
Apr 21, 2016
3,508
It's alarming to hear that multiple cyber criminals, including a potential nation-state group, were able to exploit a three-year-old Telerik bug to gain remote code execution on a US federal government agency's Microsoft Internet Information Services web server. The attack happened between November 2022 and early January and was discovered by the FBI, CISA, and MS-ISAC. The attackers were able to exploit a .NET deserialization vulnerability (CVE-2019-18935) in Progress Telerik UI for ASP.NET AJAX. The Federal agency affected has not been named.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top