• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
microsoft says chinese hackers were behind solarwinds serv u ssh 0 day

Microsoft Says Chinese Hackers Were Behind SolarWinds Serv-U SSH 0-Day Attack

You are here: Home / General Cyber Security News / Microsoft Says Chinese Hackers Were Behind SolarWinds Serv-U SSH 0-Day Attack
September 4, 2021

Microsoft has shared specialized facts about a now-fastened, actively exploited critical security vulnerability affecting SolarWinds Serv-U managed file transfer support that it has attributed with “high assurance” to a danger actor functioning out of China.

In mid-July, the Texas-centered firm remedied a distant code execution flaw (CVE-2021-35211) that was rooted in Serv-U’s implementation of the Protected Shell (SSH) protocol, which could be abused by attackers to operate arbitrary code on the contaminated technique, such as the skill to install destructive plans and check out, modify, or delete delicate data.

“The Serv-U SSH server is subject to a pre-auth distant code execution vulnerability that can be conveniently and reliably exploited in the default configuration,” Microsoft Offensive Analysis and Security Engineering workforce claimed in a detailed compose-up describing the exploit.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“An attacker can exploit this vulnerability by connecting to the open up SSH port and sending a malformed pre-auth link ask for. When successfully exploited, the vulnerability could then enable the attacker to set up or run plans, this sort of as in the case of the qualified attack we formerly documented,” the researchers added.

Though Microsoft connected the attacks to DEV-0322, a China-dependent collective citing “observed victimology, ways, and techniques,” the firm has now exposed that the distant, pre-auth vulnerability stemmed from the fashion the Serv-U procedure managed entry violations with out terminating the system, thereby generating it straightforward to pull off stealthy, dependable exploitation tries.

“The exploited vulnerability was triggered by the way Serv-U to begin with developed an OpenSSL AES128-CTR context,” the scientists explained. “This, in switch, could let the use of uninitialized information as a function pointer in the course of the decryption of successive SSH messages.”

“Consequently, an attacker could exploit this vulnerability by connecting to the open SSH port and sending a malformed pre-auth connection ask for. We also found that the attackers ended up most likely using DLLs compiled without the need of address room layout randomization (ASLR) loaded by the Serv-U course of action to aid exploitation,” the scientists added.

ASLR refers to a protection mechanism that is made use of to enhance the issue of executing a buffer overflow attack by randomly arranging the handle room positions where by process executables are loaded into memory.

Microsoft, which disclosed the attack to SolarWinds, said it advised enabling ASLR compatibility for all binaries loaded in the Serv-U procedure. “ASLR is a critical security mitigation for expert services which are uncovered to untrusted distant inputs, and demands that all binaries in the approach are appropriate in purchase to be effective at avoiding attackers from using hardcoded addresses in their exploits, as was achievable in Serv-U,” the scientists explained.

If just about anything, the revelations highlight the variety of strategies and resources applied by risk actors to breach corporate networks, which include piggybacking on legit software program.

Again in December 2020, Microsoft disclosed that a different espionage group may perhaps have been using gain of the IT infrastructure provider’s Orion software package to fall a persistent backdoor called Supernova on contaminated devices. Cybersecurity organization Secureworks linked the intrusions to a China-linked risk actor named Spiral.

Uncovered this article exciting? Comply with THN on Fb, Twitter  and LinkedIn to read far more exceptional articles we publish.


Some parts of this short article are sourced from:
thehackernews.com

Previous Post: «u.s. cyber command warns of ongoing attacks exploiting atlassian confluence U.S. Cyber Command Warns of Ongoing Attacks Exploiting Atlassian Confluence Flaw
Next Post: Apple Delays Plans to Scan Devices for Child Abuse Images After Privacy Backlash apple delays plans to scan devices for child abuse images»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.