Harmful Apache ActiveMQ Exploit Permits Stealthy EDR Bypass



A recent proof-of-concept (PoC) exploit for a essential safety vulnerability in Apache ActiveMQ is making it simpler than ever to realize distant code execution (RCE) on servers operating the open supply message dealer — avoiding discover whereas doing so.

The max-severity bug (CVE-2023-46604, CVSS rating of 10) permits unauthenticated menace actors to run arbitrary shell instructions, and it was patched by Apache late final month. Nonetheless, hundreds of organizations stay weak, a state of affairs that the HelloKitty ransomware gang and others have taken full benefit of.

Whereas assaults have to this point relied on a public PoC launched shortly after the flaw’s disclosure, researchers at VulnCheck stated this week that they’ve engineered a extra elegant exploit — one which cuts down on intruder noise by launching assaults from reminiscence.

“Meaning the menace actors may have prevented dropping their instruments to disk,” in response to VulnCheck’s submit detailing the brand new ActiveMQ exploit. “They might have simply written their encryptor in Nashorn (or loaded a category/JAR into reminiscence) and remained memory-resident, maybe avoiding detection from … managed [endpoint detection and response] EDR groups.”

New ActiveMQ Exploit: Enabling a Silent Stalker

Whereas attackers would wish to delete any incriminating log messages within the activemq.log to completely cowl their tracks, the VulnCheck PoC continues to be a major enchancment in terms of making any assaults in opposition to the vulnerability stealthier, in response to Matt Kiely, principal safety researcher at Huntress.

“The proof of idea from VulnCheck is a marked evolution from the earlier public PoCs, which usually relied on utilizing the shell of the exploited system to execute code,” he says, including that the Huntress staff confirmed that the brand new approach certainly works as marketed.

Additional, “this particular assault is trivial to take advantage of if an attacker can entry the weak occasion of ActiveMQ,” he says, including that extra evolutions and enhancements in exploit growth are positive to come back.

Thus, admins needs to be patching CVE-2023-46604 instantly, or eradicating the servers from the Web. It is also vital to bear in mind that the danger from an assault stretches nicely past ransomware, Kiely provides.

“Potential outcomes of exploitation [include] methods like account entry elimination, knowledge destruction, defacement, useful resource hijacking, and lots of others,” he explains. “Attackers might even elect to do nothing in any respect and easily wait on an exploited server to stage additional assaults” — one thing, it needs to be famous, that the silent VulnCheck PoC can extra simply allow.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top