OpenAI Patches Account Takeover Vulnerabilities in ChatGPT

Last week, ChatGPT creator OpenAI patched multiple severe vulnerabilities that could have allowed attackers to take over user accounts and view chat histories.

The first was a critical web cache deception bug that could have allowed attackers to access user information such as names, emails, and access tokens, which OpenAI’s API would fetch from the server.

To exploit the vulnerability, an attacker could craft a .css path to the session endpoint and send the link to the victim. When the victim opens the link, the response is cached and the attacker can harvest the victim’s credentials and take over their account.

Reported by Shockwave CEO and founder Gal Nagli, the bug was quickly addressed by instructing “the caching server to not catch the endpoint through a regex”.

The fix, however, was not enough to keep an attacker out of user accounts, security researcher and CISO Ayoub Fathi explains. While analyzing the fix, he discovered a bypass method that could be used against another ChatGPT API, providing an attacker with access to a user’s conversation titles.

This was basically another web cache deception attack: the API response to a forged ‘/backend-api/conversations’ link would be cached, revealing the victim’s HTTP response, which contains the conversations’ titles.

Digging deeper, the researcher was able to bypass OpenAI’s fix for the original account takeover issue, using a new payload, and discovered that all ChatGPT APIs were vulnerable to the bypass, allowing an attacker to read conversation titles, full chats, and account status.

Fathi says he worked with the OpenAI team to help them fully address all issues.

No bug bounty reward was issued to either researcher, as OpenAI does not have a bug bounty program in place.

The vulnerabilities were reported days after OpenAI took ChatGPT offline to address a vulnerability in an open-source Redis client library, which allowed users to view other users’ chat data and payment-related information.

Related: ChatGPT Data Breach Confirmed as Security Firm Warns of Vulnerable Component Exploitation

Related: Microsoft Puts ChatGPT to Work on Automating Cybersecurity

Related:ChatGPT and the Growing Threat of Bring Your Own AI to the SOC

OpenAI Patches Account Takeover Vulnerabilities in ChatGPT




OpenSSL 1.1.1 Nears End of Life: Security Updates Only Until September 2023

OpenSSL 1.1.1 will reach end of life (EoL) in less than six months and users have been instructed to either upgrade to a newer version or pay for extended support to continue receiving security patches. 

The OpenSSL Project has reminded users of the open source cryptography and secure communication toolkit that OpenSSL 1.1.1 will reach EoL on September 11, 2023, exactly five years after its release. 

After this date, OpenSSL 1.1.1 users will no longer receive security updates, unless they pay for a premium support plan, which provides extended support beyond the EoL date. 

Premium level support is designed for large enterprises and it costs $50,000 per year. 

“There is no defined end date for this extended support and we intend to continue to provide it for as long as it remains commercially viable for us to do so (i.e. for the foreseeable future),” the OpenSSL Project explained in a blog post on Tuesday. 

Users who want to continue receiving security updates without paying for a premium plan will have to upgrade to a newer version. The most recent, OpenSSL 3.1, will be supported until March 2025. OpenSSL 3.0, which is a long term support (LTS) release, will be supported until September 2026.

LTS releases are supported for five years — this is the case of OpenSSL 1.1.1 — and during the last year the project’s maintainers typically only backport security fixes to a release.

OpenSSL has evolved significantly in terms of security since the disclosure of the Heartbleed vulnerability back in 2014. 

Since the beginning of 2022, two dozen vulnerabilities have been found in the project, including five high-severity issues that could lead to denial-of-service (DoS) attacks or arbitrary code execution. One of the high-severity flaws was patched in February 2023. 

Related: ICS Patch Tuesday: Siemens Fixes 80 OpenSSL, OpenSSH Flaws in Switches

Related: Anxiously Awaited OpenSSL Vulnerability’s Severity Downgraded From Critical to High

Related: Cybersecurity Vendors Assessing Impact of Recent OpenSSL Vulnerability

https://www.securityweek.com/openssl-1-1-1-nears-end-of-life-security-updates-only-until-september-2023/




Google Links More iOS, Android Zero-Day Exploits to Spyware Vendors

Several zero-day vulnerabilities patched last year had been exploited by commercial spyware vendors to target Android and iOS devices, according to a report published on Wednesday by Google’s Threat Analysis Group (TAG). 

Google’s security researchers have detailed the zero-day and n-day vulnerabilities exploited in what they described as two different highly targeted campaigns. For many of the zero-days, no information was available until now on the attacks exploiting them. 

The internet giant has been tracking more than 30 spyware vendors that provide exploits and surveillance solutions to governments. While the surveillance technologies themselves may not be illegal — they are typically advertised as solutions designed for official intelligence and law enforcement operations — the problem is that they are often used by governments to target the opposition, journalists, and dissidents. 

In one of the two campaigns described by Google on Wednesday, an attack started with a link being sent to the targeted user via SMS. When clicked, the link took the victim to malicious websites delivering Android or iOS exploits — depending on the target’s device. Once the exploits were delivered, victims were redirected to legitimate websites, likely in an effort to avoid raising suspicion. 

The iOS exploit chain involved CVE-2022-42856, a WebKit vulnerability that Apple patched in iPhones in December 2022 with an iOS update. Attacks also involved a Pointer Authentication (PAC) bypass technique, and an exploit for CVE-2021-30900, a sandbox escape and privilege escalation vulnerability that Apple patched in iOS in 2021. 

The Android exploit chain targeted CVE-2022-3723, a Chrome zero-day fixed by Google in October 2022. 

It also targeted CVE-2022-4135, a Chrome flaw that Google patched in November 2022 — it was the eighth Chrome zero-day of 2022. This is a Chrome GPU sandbox bypass that only impacts Android devices. 

The Android chain also included exploitation of CVE-2022-38181, an Arm Mali GPU vulnerability leading to arbitrary kernel code execution and root on Pixel 6 phones. A patch was released by Arm in August 2022, but it was only rolled out to Pixel devices in January 2023. 

“When Arm released a fix for CVE-2022-38181, several vendors, including Pixel, Samsung, Xiaomi, Oppo and others, did not incorporate the patch, resulting in a situation where attackers were able to freely exploit the bug for several months,” Google said, noting that it’s unclear if attackers had been exploiting the flaw before it was responsibly disclosed to Arm.

This campaign targeted users in Italy, Malaysia and Kazakhstan.

Google reported last year that Apple and Android smartphones in Italy and Kazakhstan had been targeted using spyware made by Italian company RCS Lab. However, Google noted in its new blog post that one of the techniques used against iOS devices has also been leveraged by the Predator spyware, made by North Macedonian spyware vendor Cytrox.

In the second campaign, discovered in December 2022, the attackers targeted the Samsung Internet Browser by chaining various zero-day and n-day vulnerabilities. 

In this campaign as well, the exploits were delivered as links sent via SMS. The attacks were aimed at users in the United Arab Emirates and the goal was the delivery of full-featured Android spyware. 

Google believes the attack was carried out by a customer or partner of Variston, a Spanish commercial spyware vendor whose exploitation frameworks were described by the internet giant last year. 

The attackers exploited several Chrome vulnerabilities. The Samsung browser is based on Chromium, which means it’s impacted by the same flaws as Chrome. However, the Samsung browser does not include some mitigations that would have made exploitation more difficult. 

The list of exploits included CVE-2022-4262, a Chrome zero-day fixed by Google in December 2022, and CVE-2022-3038, a Chrome sandbox escape.

The campaign also targeted CVE-2022-22706, a Mali GPU kernel driver issue fixed by Arm in January 2022, and CVE-2023-0266, a Linux kernel sound subsystem flaw that gives the attacker kernel read and write access. Both of these vulnerabilities were exploited in the wild against Android devices before patches were released. 

Google has made available indicators of compromise (IoCs) that can be used to detect these attacks. 

Related: Google Reveals Spyware Vendor’s Use of Samsung Phone Zero-Day Exploits

Related: US to Adopt New Restrictions on Using Commercial Spyware

Related: Leaked Docs Show Spyware Firm Offering iOS, Android Hacking Services for $8 Million

https://www.securityweek.com/google-links-more-ios-android-zero-day-exploits-to-spyware-vendors/




ChatGPT Data Breach Confirmed as Security Firm Warns of Vulnerable Component Exploitation

ChatGPT creator OpenAI has confirmed a data breach caused by a bug in an open source library, just as a cybersecurity firm noticed that a recently introduced component is affected by an actively exploited vulnerability.

OpenAI said on Friday that it had taken the chatbot offline earlier in the week while it worked with the maintainers of the Redis data platform to patch a flaw that resulted in the exposure of user information. 

The issue was related to ChatGPT’s use of Redis-py, an open source Redis client library, and it was introduced by a change made by OpenAI on March 20. 

The chatbot’s developers use Redis to cache user information in their server, to avoid having to check the database for every request. The Redis-py library serves as a Python interface. 

The bug introduced by OpenAI resulted in ChatGPT users being shown chat data belonging to others.

According to OpenAI’s investigation, the titles of active users’ chat history and the first message of a newly created conversation were exposed in the data breach. The bug also exposed payment-related information belonging to 1.2% of ChatGPT Plus subscribers, including first and last name, email address, payment address, payment card expiration date, and the last four digits of the customer’s card number. 

This information may have been included in subscription confirmation emails sent on March 20 and it may have also been displayed in the subscription management page in ChatGPT accounts on the same day. OpenAI has confirmed that the information was exposed during a nine-hour window on March 20, but admitted that information may have been leaked prior to March 20 as well. 

“We have reached out to notify affected users that their payment information may have been exposed. We are confident that there is no ongoing risk to users’ data,” OpenAI said in a blog post. 

The blog post describes the technical details of the issue and the action taken by the company in response.

This was not the only ChatGPT security issue that came to light last week. Also on Friday, threat intelligence company GreyNoise issued a warning regarding a new ChatGPT feature that expands the chatbot’s information collecting capabilities through the use of plugins. 

GreyNoise noticed that the code examples provided by OpenAI to customers interested in integrating their plugins with the new feature include a docker image for the MinIO distributed object storage system. 

The docker image version used in OpenAI’s example, release 2022-03-17, is affected by CVE-2023-28432, a potentially serious information disclosure vulnerability. The security hole can be leveraged to obtain secret keys and root passwords and GreyNoise has already seen attempts to exploit the vulnerability in the wild. 

“While we have no information suggesting that any specific actor is targeting ChatGPT example instances, we have observed this vulnerability being actively exploited in the wild. When attackers attempt mass-identification and mass-exploitation of vulnerable services, ‘everything’ is in scope, including any deployed ChatGPT plugins that utilize this outdated version of MinIO,” the security firm warned. 

Related: ChatGPT Integrated Into Cybersecurity Products as Industry Tests Its Capabilities

Related: ChatGPT and the Growing Threat of Bring Your Own AI to the SOC

Related: ‘Grim’ Criminal Abuse of ChatGPT is Coming, Europol Warns 

https://www.securityweek.com/chatgpt-data-breach-confirmed-as-security-firm-warns-of-vulnerable-component-exploitation/




Microsoft: No-Interaction Outlook Zero Day Exploited Since Last April

Microsoft says it has evidence that Russian APT actors were exploiting a nasty Outlook zero-day as far back as April 2022, a disclosure that ups the stakes on organizations to start hunting for signs of compromise.

The vulnerability, tracked as CVE-2023-23397, was flagged in the ‘already exploited’ category when Redmond shipped a fix earlier this month and Microsoft’s incident responders have pinned the attacks on Russian government-level hackers targeting organizations in Europe.

“Microsoft has traced evidence of potential exploitation of this vulnerability as early as April 2022,” the company said in fresh documentation that provides guidance for investigating attacks linked to the Outlook flaw.

Microsoft warned that exploitation of the critical-severity bug “leaves very few forensic artifacts to discover in traditional endpoint forensic analysis” and urged defenders in the targeted sectors to use “an in-depth and comprehensive threat hunting strategy” to ferret out the nation-state hacking teams.

Microsoft has pinned the blame for the attacks on an unidentified “Russian-based threat actor” seen hitting a limited number of organizations in government, transportation, energy, and military sectors in Europe.

In a nod to the severity of the issue, the Microsoft Security Response Center (MSRC) previously published mitigation guidance and provided a CVE-2023-23397 script to help with audit and cleanup and now the company is going further with threat-hunting tips and guidance for defenders.

Microsoft noted that the vulnerability triggers a Net-NTLMv2 hash leak that has been abused for initial access, credential access and lateral movement and even persistence in compromised mailboxes.

The company is recommending that defenders be strategic about hunting for infections linked to the Outlook for Windows vulnerability.  Microsoft is recommending that defenders:

  • Review suspicious messages, calendar items, or tasks with reminders that were reported by users
  • Examine network logging and endpoint logging for evidence of known atomic indicators
  • Scan Exchange for delivered messages with the PidLidReminderFileParameter set
  • Hunt for anomalous behaviors based on:
    • NTLM authentication involving untrusted or external resources. This can be observed in Exchange Server logging, Microsoft Defender for Identity, and Microsoft Defender for Endpoint telemetry.
    • WebDAV connection attempts through process execution events.
    • SMBClient event log entries.
    • Firewall logs for suspicious outbound SMB connection

Microsoft also shipped a CVE-2023-23397 detection script and urged organizations to review the output of this script to determine whether an exploit was successful. 

Because this flaw could lead to exploitation BEFORE the email is viewed in the Preview Pane, enterprise security teams are urged to prioritize the deployment of this update. 

Related: Microsoft Warns of Outlook Zero-Day Exploitation, Patches 80 Vulns

Related: Microsoft Pins Outlook Zero-Day Attacks on Russians, Offers Detection Script

Related: Tesla Hacked Twice at Pwn2Own Exploit Contest

Related: CISA Ships ‘Untitled Goose Tool’ to Hunt for Azure Cloud Infections

https://www.securityweek.com/microsoft-no-interaction-outlook-zero-day-exploited-since-last-april/




Hackers Earn Over $1 Million at Pwn2Own Exploit Contest

Security researchers participating in this year’s Pwn2Own software exploitation contest banked more than $1 million in prizes over three days, organizers announced over the weekend.

The highest reward on the first day of the contest was earned for a TOCTOU (time-of-check to time-of-use) race condition exploit used to take full control of a Tesla vehicle. Researchers at French offensive security firm Synacktiv pocketed a $100,000 cash prize and ownership of a Tesla Model 3 car.

On the same day, a two-bug chain against Microsoft SharePoint was awarded a $100,000 prize and a six-bug logic chain targeting Adobe Reader earned hackers a $50,000 prize.

Vulnerabilities in Oracle VirtualBox ($40,000), Apple macOS ($40,000), Windows 11 ($30,000), and Ubuntu (two bugs, two $30,000 prizes) were also rewarded.

The first day of the contest ended with 12 zero-days being disclosed and $375,000 in cash and a car awarded in prizes.

The highest prize of the second day ($150,000) was once again earned for a Tesla hack, once again by the Synacktiv team. The exploit qualified for a Tier 2 award and the team earned $250,000.

Synacktiv emerged as the winner of Pwn2Own Vancouver 2023, earning a total of $530,000 and a car over the course of the three-day event.

VirtualBox was hacked twice on the second day of the competition, for $80,000 and $40,000 prizes, respectively. Microsoft Teams ($75,000) and Ubuntu ($30,000) were also hacked.

The second day ended with $475,000 awarded for 10 unique zero-days.

The STAR Labs team earned the highest prizes on the third day of the competition, one for a VMware Workstation exploit ($80,000) and another for a Microsoft Teams exploit ($75,000).

On the same day, three prizes of $30,000 were earned for Ubuntu hacks and another one for a Windows 11 exploit.

Related: Hackers Earn $180,000 for ICS Exploits at Pwn2Own Miami 2023

Related: Netgear Neutralizes Pwn2Own Exploits With Last-Minute Nighthawk Router Patches

Related: Pwn2Own Offers $100,000 for Home Office Hacking Scenario

https://www.securityweek.com/hackers-earn-over-1-million-at-pwn2own-exploit-contest/




GoAnywhere Zero-Day Attack Hits Major Orgs

More organizations are emerging to confirm impact from the newly disclosed in-the-wild zero-day exploits hitting Fortra’s GoAnywhere managed file transfer (MFT) software.

Tracked as CVE-2023-0669, the vulnerability was publicly disclosed in early February alongside zero-day exploitation and a patch was released a week later.

Soon after, attacks targeting the security defect were linked to a Russian-speaking threat actor called ‘Silence’ that has been linked to the distribution of the Cl0p ransomware.

Over the past week, the ransomware group started posting on their Tor-based leak site the names of organizations allegedly impacted by the incident, including the City of Toronto, luxury brand retailer Saks Fifth Avenue, American education platform Pluralsight, consumer goods giant Procter & Gamble, mining company Rio Tinto, and the U.K.’s Pension Protection Fund (PPF).

Previously, sustainable energy giant Hitachi Energy, California-based digital bank Hatch Bank, cybersecurity firm Rubrik, and healthcare provider Community Health Systems confirmed impact from the GoAnywhere attack.

Responding to a SecurityWeek inquiry, the City of Toronto confirmed that some data was compromised in an incident at a third-party vendor, without specifically naming Fortra’s GoAnywhere service.

“The access is limited to files that were unable to be processed through the third-party secure file transfer system. The City is actively investigating the details of the identified files,” a City of Toronto official said.

Saks Fifth Avenue confirmed that some of its data was stolen following the GoAnywhere incident but claimed that no real customer data was impacted.

“Fortra, a vendor to Saks and many other companies, recently experienced a data security incident that led to mock customer data being taken from a storage location used by Saks. The mock customer data does not include real customer or payment card information and is solely used to simulate customer orders for testing purposes,” Saks told SecurityWeek.

Pluralsight says that it immediately discontinued the use of GoAnywhere after Fortra informed them of the incident, and that it also notified all affected customers of the risks associated with the attack.

In a statement on its website, PPF says that employee data was compromised in the GoAnywhere incident, and that it stopped using the service immediately after learning that.

P&G has confirmed that some employee data was stolen in the incident, but said the incident did not impact customer data, Social Security numbers or financial information.

Virgin confirmed not only the impact from the incident, but also that the Cl0p gang contacted them directly to claim possession of stolen data. “We were recently contacted by a ransomware group, calling themselves Cl0p, who illegally obtained some Virgin Red files via a cyber-attack on our supplier, GoAnywhere. The files in question pose no risk to customers or employees as they contain no personal data,” a Virgin Red spokesperson told SecurityWeek.

French digital transformation and hybrid cloud company Atos on Friday announced that the GoAnywhere incident impacted data associated with a specific Nimbix file transfer application.

“Our cybersecurity team has identified a backup folder from 2016 that was presumably exposed, due to a zero-day vulnerability known to be exploited by Cl0p. We are in contact with the clients concerned,” the company said.

According to Reuters, Rio Tinto informed employees last week that internal data, such as payroll information, was stolen in the GoAnywhere attack, and that the group responsible for the hack was threatening to release the data publicly. Rio Tinto did not respond to a SecurityWeek request for comment.

Related: NBA Notifying Individuals of Data Breach at Mailing Services Provider

Related: Latitude Financial Services Data Breach Impacts 300,000 Customers

Related: Data Breach at Independent Living Systems Impacts 4 Million Individuals

https://www.securityweek.com/goanywhere-zero-day-attack-hits-major-orgs/




Tesla Hacked Twice at Pwn2Own Exploit Contest

Researchers at French offensive hacking shop Synacktiv have demonstrated a pair of successful exploit chains against Tesla’s newest electric car to take top billing at the annual Pwn2Own software exploitation contest.

Pwn2Own organizers confirmed the successful hacks exploited flaws in the Tesla-Gateway and Tesla-Infotainment sub-systems to “fully compromise” a new Tesla Model 3 vehicle.

The first Tesla hack, described as a TOCTOU (time-of-check to time-of-use) race condition, earned the hackers a $100,000 cash prize and ownership of the compromised car.  Synacktiv said the Tesla Model 3 gateway was fully compromised from the ethernet network.

SecurityWeek sources say Tesla security response team was on site at the event and validated the findings.  The company is expected to issue fixes via the vehicle’s self-updating system.

On the second day of the contest in Vancouver, Canada, Synacktiv’s researchers created an exploit chain that used a heap overflow and an out-of-band (OOB) write vulnerability to pop the Tesla-Infotainment system.  The hack was described as “Unconfined Root” and scored the Synacktiv team a $250,000 cash prize.

Tesla Exploits
Image credit: Zero Day Initiative

Tesla is a Pwn2Own co-sponsor and is using the annual contest to incentivize security researchers to showcase complex exploit chains that can lead to complete vehicle compromise. 

This isn’t the first time Tesla has sought to attract the attention of advanced exploit writers at Pwn2Own. Back in 2019, the company gave away a Tesla Model 3 to a pair of researchers demonstrating successful exploits and this year the organizers plan to raise the level of complexity of what constitutes a successful car-hacking exploit.

This year, the organizers were looking to attract exploits targeting Tesla’s Tuner, Wi-Fi, Bluetooth or Modem components.   

Related: Tesla Returns as Pwn2Own Hacker Takeover Target

Related: Pwn2Own 2019: Researchers Win Tesla After Hacking Its Browser 

Related: $200,000 Awarded for Zoom Zero-Click Zoom Exploit at Pwn2Own

Related: Over $1.1 Million Awarded at Pwn2Own 2022 for 25 Zero-Day Vulns

https://www.securityweek.com/tesla-hacked-twice-at-pwn2own-exploit-contest/




Critical WooCommerce Payments Vulnerability Leads to Site Takeover

A critical vulnerability in the open-source WooCommerce Payments plugin for WordPress could allow attackers to impersonate any user on the site and potentially take over site administrator accounts.

Developed by Automattic and installed on more than 500,000 websites, the WooCommerce Payments plugin is a fully integrated payment solution for WooCommerce that provides transaction management directly from the store’s dashboard.

On Thursday, Automattic updated WooCommerce Payments to version 5.6.2 to address a privilege escalation vulnerability that could allow an unauthenticated attacker to gain control of an administrator’s account and completely take over a vulnerable website.

“This could allow a malicious user to escalate their regular guest privileges to the privileges of an administrator and further exploit the website. As this vulnerability requires no authentication, it is very likely it will be mass-exploited very soon,” according to an advisory from WordPress security firm Patchstack.

According to Defiant’s Wordfence team, the issue exists in “functionality designed to integrate with the WooCommerce Payment Platform”. No further details on the security defect have been released, given that it is rated ‘critical severity’ (CVSS score of 9.8).

Reported by Michael Mazzolini of GoldNetwork, the vulnerability could potentially impact WooCommerce’s new WooPay payment checkout service (currently in beta testing). The beta program has been temporarily disabled.

For sites running WooCommerce Payments 4.8.0 through 5.6.1 that are hosted on WordPress.com, automatic updates are being rolled out. The administrators of all other WordPress websites using a vulnerable plugin version need to update their installations manually.

“All websites with WooCommerce Payments 4.8.0 and higher installed and activated on their site, that are not hosted on WordPress.com and which have not updated to a patched version, are still potentially vulnerable to this issue,” the WooCommerce team said.

WooCommerce says it currently has no evidence that this vulnerability is being exploited in attacks or that store or customer data might have been compromised because of it.

Related: Vulnerability in Popular Real Estate Theme Exploited to Hack WordPress Websites

Related: Critical Vulnerability in Premium Gift Cards WordPress Plugin Exploited in Attacks

Related: WordPress Sites Hacked via Zero-Day Vulnerability in WPGateway Plugin

https://www.securityweek.com/critical-woocommerce-payments-vulnerability-leads-to-site-takeover/




PoC Exploit Published for Just-Patched Veeam Data Backup Solution Flaw

Security researchers have published proof-of-concept (PoC) code that provides a roadmap to exploit a recently patched high-severity vulnerability in the Veeam Backup & Replication product

Earlier this month, Veeam released a patch for CVE-2023-27532 (CVSS score of 7.5), a security defect the company warned could be exploited to obtain encrypted credentials that are stored in the configuration database.

Successful exploitation of the issue, Veeam said, could allow an attacker to access the backup infrastructure hosts. Unpatched publicly exposed Veeam instances with a TCP port 9401 open could become easy targets to attackers.

A few days after Veeam’s patch release, anti-malware company Huntress said that there might be thousands of hosts running vulnerable versions of the solution, urging users to update their installations as soon as possible.

Patching is now critical, as Horizon3.ai has released proof-of-concept code targeting the flaw, along with a technical writeup of the vulnerability and the exploitation process.

“CVE-2023-27532 allows an unauthenticated user with access to the Veeam backup service to request cleartext credentials. We have examined the vulnerable port, reverse engineered the Veeam Backup Service, and constructed a WCF client using .NET core,” Horizon3.ai warned.

The vulnerability was addressed with the release of Veeam Backup & Replication versions 12 (build 12.0.0.1420 P20230223) and 11a (build 11.0.1.1261 P20230227), which need to be installed on the Veeam Backup & Replication server.

While there are no reports of CVE-2023-27532 being exploited in attacks, it might not be long before exploitation begins. Threat actors have been known to target Backup & Replication flaws in their attacks. 

Veeam Backup & Replication is a backup solution for virtual environments that offers support for cloud-based workloads servers, and workstations, and for Hyper-V, Nutanix AHV, and vSphere virtual machines.

Related: Exploitation of Oracle E-Business Suite Flaw Starts After PoC Publication

Related: Exploitation of Control Web Panel Vulnerability Starts After PoC Publication

Related: PoC Code Published for High-Severity macOS Sandbox Escape Vulnerability

https://www.securityweek.com/poc-exploit-published-for-just-patched-veeam-data-backup-solution-flaw/