• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
patch your goanywhere mft immediately critical flaw lets anyone

Patch Your GoAnywhere MFT Immediately – Critical Flaw Lets Anyone Be Admin

You are here: Home / General Cyber Security News / Patch Your GoAnywhere MFT Immediately – Critical Flaw Lets Anyone Be Admin
January 24, 2024

A critical security flaw has been disclosed in Fortra’s GoAnywhere Managed File Transfer (MFT) computer software that could be abused to generate a new administrator consumer.

Tracked as CVE-2024-0204, the issue carries a CVSS rating of 9.8 out of 10.

“Authentication bypass in Fortra’s GoAnywhere MFT prior to 7.4.1 makes it possible for an unauthorized person to develop an admin consumer via the administration portal,” Fortra claimed in an advisory introduced on January 22, 2024.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Cybersecurity

Users who can not up grade to edition 7.4.1 can implement non permanent workarounds in non-container deployments by deleting the InitialAccountSetup.xhtml file in the install listing and restarting the solutions.

For container-deployed occasions, it’s proposed to replace the file with an vacant file and restart.

Mohammed Eldeeb and Islam Elrfai of Cairo-based Spark Engineering Consultants have been credited with finding and reporting the flaw in December 2023.

Cybersecurity firm Horizon3.ai, which posted a proof-of-concept (PoC) exploit for CVE-2024-0204, said the issue is the consequence of a route traversal weakness in the “/InitialAccountSetup.xhtml” endpoint that could be exploited to make administrative consumers.

“The simplest indicator of compromise that can be analyzed is for any new additions to the Admin Customers group in the GoAnywhere administrator portal Customers -> Admin People part,” Horizon3.ai security researcher Zach Hanley explained.

Cybersecurity

“If the attacker has still left this consumer listed here you may well be ready to notice its very last logon action listed here to gauge an approximate date of compromise.”

Even though there is no proof of active exploitation of CVE-2024-0204 in the wild, a different flaw in the exact merchandise (CVE-2023-0669, CVSS rating: 7.2) was abused by the Cl0p ransomware group to breach just about 130 victims last calendar year.

Observed this article appealing? Observe us on Twitter  and LinkedIn to go through more special material we post.


Some elements of this post are sourced from:
thehackernews.com

Previous Post: «vextrio: the uber of cybercrime brokering malware for 60+ VexTrio: The Uber of Cybercrime – Brokering Malware for 60+ Affiliates
Next Post: U.S., U.K., Australia Sanction Russian REvil Hacker Behind Medibank Breach u.s., u.k., australia sanction russian revil hacker behind medibank breach»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.