MoveIT Transfer Vulnerability and Supply Chain Attacks
In the realm of cyber threats, supply chain attacks have emerged as a formidable tactic employed by cybercriminals, threatening the security and operational integrity of businesses worldwide. Herein, we will delve into the nature of supply chain attacks, the impact they can have on victimized companies, effective prevention strategies, and notable recent cases.
Understanding Supply Chain Attacks
Historically, supply chain attacks were directed at the relationships of trust within a chain, specifically targeting a vulnerable supplier to infiltrate larger business partners. Today, however, the more pressing concern lies with software supply chain attacks. Given the fact that contemporary software frequently relies on a plethora of pre-made elements, like third-party APIs, open source code, and proprietary software vendor code, this makes the software supply chain especially susceptible to attacks. If there is a security breach in one dependency of a well-known app, all businesses using this vendor's services can potentially be compromised.
Several types of supply chain attacks exist, including attacks on upstream servers, midstream attacks, dependency confusion attacks, theft of SSL and code-signing certificates, attacks on CI/CD infrastructure, and open source software attacks. Notable instances of supply chain attacks include the SolarWinds attack, the ASUS Live Utility attack, the attack on Browserify - an open-source JavaScript tool, and the compromise of the widely used free cleanup tool, CC Cleaner. To prevent and detect these supply chain attacks, it's crucial to utilize robust prevention, detection, and response technologies. Such solutions would include behavior-based attack detection, threat intelligence to anticipate future supply chain attacks, and proactive services incorporating supply chain analysis.
What is MOVEit Transfer Vulnerability (CVE-2023-34362)
The vulnerability CVE-2023-34362 pertains to the MOVEit Transfer application. It is a SQL injection vulnerability found in versions before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1) of the MOVEit Transfer web application. All versions before the five explicitly mentioned are affected, including older unsupported versions. This vulnerability could allow an unauthenticated attacker to gain access to the MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. It's noteworthy that this vulnerability has been exploited in the wild in May and June 2023, with exploitation of unpatched systems occurring via HTTP or HTTPS. As of June 2, 2023, CVE-2023-34362 has been assigned to this vulnerability. On Friday, June 9, Progress Software released patches for a second vulnerability, CVE-2023-35036. On Thursday, June 15, a third vulnerability was announced and later assigned CVE-2023-35708.
This vulnerability has been assigned a severity score of 9.8, making it a critical threat. The vector string for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The advised action to mitigate this vulnerability is to apply updates as per vendor instructions. Cybersecurity company Rapid7 estimates that the majority of the roughly 2,500 online instances of MOVEit are running in the U.S. The Cl0p ransomware gang has continued to target systems that still aren't patched, according to a U.S. government advisory.
SentinelOne observed active exploitation of Windows servers running a vulnerable version of Progress Software’s MOVEit Transfer file server application. The attack delivers a minimal webshell that the attacker can use to exfiltrate the contents of files, including files hosted in Microsoft Azure when the targeted MOVEit instance is configured to use Azure’s blob storage service. The attack chain leverages this vulnerability to conduct an arbitrary file upload via the moveitsvc service account to the server’s \\MOVEitTransfer\\wwwroot\\ directory. The system’s svchost.exe process launches w3wp.exe, a Microsoft Internet Information Service (IIS) worker process, which then writes several files to a new working directory in Temp. The actor’s choice to use the MOVEit flaw to target files in Azure cloud storage is notable. A bespoke webshell designed to steal Azure files through SQL queries specific to the targeted environment represents a notable departure from this established norm and suggests the tooling was likely developed and tested well in advance of in-the-wild (ITW) attacks.
Progress has released a patch for this vulnerability, and all MOVEit Transfer customers are urged to apply it as soon as possible. In the meantime, there are a few steps that you can take to mitigate the risk of exploitation:
- Disable all HTTP and HTTPS traffic to your MOVEit Transfer environment.
- Review your firewall rules to ensure that they block all traffic to MOVEit Transfer on ports 80 and 443.
- Monitor your MOVEit Transfer environment for any signs of suspicious activity.
If you have any questions or concerns about this vulnerability, please contact Progress Software Corporation.
What are the worst-case scenarios for being a victim of a supply chain attack?
Supply chain attacks can have severe consequences for organizations, leading to a variety of worst-case scenarios. Here are some of the potential outcomes:
-
Loss of Sensitive Data: One of the most devastating impacts of a supply chain attack can be the loss or theft of sensitive data. This could include customer data, intellectual property, or internal communications. The exposure of this data can lead to financial losses, damage to an organization's reputation, and potential legal consequences if the data includes personally identifiable information (PII) of customers or employees.
-
Operational Disruption: A successful supply chain attack can cause significant disruption to an organization's operations. If an attacker is able to gain control of systems or applications, they may be able to halt operations or manipulate processes. This can lead to a loss of productivity and revenue.
-
Financial Impact: The financial impact of a supply chain attack can be significant. This includes not only the potential loss of revenue during any operational disruption, but also the costs associated with investigating the attack, recovering from it, and implementing additional security measures to prevent future attacks. Additionally, organizations could face fines or lawsuits if the attack results in a data breach.
-
Damage to Reputation: Being the victim of a supply chain attack can cause severe damage to an organization's reputation. Customers, partners, and stakeholders may lose trust in the organization's ability to protect its data and systems, which can lead to lost business.
-
Impact on Partners and Customers: A supply chain attack can extend beyond the initially targeted organization. If an attacker is able to compromise a product or service, they may be able to use that as a stepping stone to launch attacks against the organization's customers or partners. This can lead to a ripple effect, causing damage and disruption to a wide range of entities.
-
National Security Implications: In some cases, a supply chain attack can have implications for national security. This is particularly true if the attack targets critical infrastructure or government agencies. In these situations, a successful attack could disrupt essential services and potentially pose a threat to public safety.
How can companies protect themselves from supply chain attacks?
Vendor risk management is a crucial strategy for protecting against supply chain attacks. It involves developing a program to assess and manage the risks associated with your supply chain. This could entail conducting regular audits and assessments of your suppliers' security measures and understanding their data management practices. By closely scrutinizing your suppliers, you can gain a clearer picture of the vulnerabilities in your supply chain and take steps to address them. In addition to managing vendor risks, it's essential to educate your workforce about the risks associated with supply chain attacks. A robust security awareness training program can equip employees to recognize and respond to potential threats. This training can include lessons on identifying phishing attacks, using the internet safely, and understanding the importance of regularly updating and patching software.
Regular software updates and effective patch management are also key in protecting against supply chain attacks. This involves not only maintaining your own software but also monitoring any software provided by your suppliers. By keeping all software up-to-date, you can minimize the vulnerabilities that attackers might exploit. Network segmentation is another valuable strategy. By dividing your network into separate segments, you can limit the spread of a potential attack. If one part of your network is compromised, network segmentation can help to prevent the attacker from gaining access to other parts of your network, thereby containing the damage.
Implementing multi-factor authentication (MFA) can provide an additional layer of security. MFA requires users to present two or more pieces of evidence (or factors) to verify their identity before gaining access to a system. This could include something they know (like a password), something they have (like a mobile device), or something they are (like a fingerprint). Monitoring network activity and detecting anomalies are crucial for identifying potential supply chain attacks. Security information and event management (SIEM) systems and intrusion detection systems (IDS) can monitor network activity and identify unusual patterns that might indicate an attack. By detecting these anomalies, you can respond to threats more rapidly and potentially prevent an attack from escalating.
Having a well-developed incident response plan is vital. This plan should outline the steps to take in the event of a security breach, including identifying the breach, containing the damage, eradicating the threat, recovering, and learning from the incident. A robust response plan can minimize the impact of an attack and reduce recovery time.
Secure software development practices are also an important part of preventing supply chain attacks. This means ensuring that software is developed with security in mind from the outset, which can include code reviews, using automated security tools, and continuous testing to catch and fix vulnerabilities before they can be exploited. Third-party cybersecurity assessments can also be beneficial. By having an independent party assess your security measures, you can gain a fresh perspective on potential vulnerabilities and receive advice on how to address them.
Finally, while it won't prevent an attack, cyber insurance can offer financial protection in the event of a cyber attack, including a supply chain attack. This can help cover the costs associated with recovery and could provide vital support in the aftermath of an attack.
Each of these strategies plays a role in a holistic approach to cybersecurity. By combining these strategies, organizations can enhance their resilience against supply chain attacks and minimize the potential damage they can cause.