Exploit für kritischen WhatsUp Gold RCE-Fehler veröffentlicht, jetzt patchen

Teilen:

A proof-of-concept (PoC) exploit for a critical-severity remote code execution flaw in Progress WhatsUp Gold has been published, making it critical to install the latest security updates as soon as possible.

The flaw is tracked as CVE-2024-8785 (CVSS v3.1 score: 9.8) and was discovered by Tenable in mid-August 2024. It exists in the NmAPI.exe process in WhatsUp Gold versions from 2023.1.0 and before 24.0.1.

Manipulating the Windows Registry

When launched, NmAPI.exe provides a network management API interface for WhatsUp Gold, listening for and processing incoming requests.

Due to insufficient validation of incoming data, attackers could send specially crafted requests to modify or overwrite sensitive Windows registry keys that control where WhatsUp Gold configuration files are read from.

“An unauthenticated remote attacker can invoke the UpdateFailoverRegistryValues operation via a netTcpBinding at net.tcp://<target-host>:9643,” reads Tenable’s writeup.

“Through the UpdateFailoverRegistryValues operation, the attacker can change an existing registry value or create a new one for any registry path under HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.”

“Specifically, the attacker can change HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\Network Monitor\WhatsUp Gold\Setup\InstallDir to a UNC path pointing to a host controlled by the attacker (i.e., \\<attacker-ip>\share\WhatsUp).”

The next time the Ipswitch Service Control Manager service restarts, it will read various configuration files from the attacker-controlled remote share, which can be used to start any remote executable the attacker wishes on the vulnerable WhatsUp Gold system.

Apart from the obvious risks that arise from such a scenario, the ability to modify the system registry also gives the attack excellent persistence capabilities, like making changes to startup keys so malicious code is executed upon system boot.

Exploitation of CVE-2024-8785 does not require authentication, and since the NmAPI.exe service is accessible over the network, the risk is significant.

Update WhatsUp Gold now

System administrators managing WhatsUp Gold deployments should upgrade to version 24.0.1 as soon as possible.

Progress Software released security updates addressing CVE-2024-8785 and five more flaws on September 24, 2024, and published the related bulletin here, containing installation instructions.

WhatsUp Gold has been targeted by hackers again recently, with the threat actors leveraging publicly available exploits to attack vulnerable endpoints.

In early August, threat actors used public PoCs for a critical WhatsUp Gold RCE flaw to gain initial access to corporate networks.

In September, hackers used public exploits for two critical SQL injection vulnerabilities in WhatsUp Gold, which enabled them to take over administrator accounts without knowing the password.

Given the recent history of threat actors exploiting critical vulnerabilities in Progress Software’s popular network monitoring solution, it’s imperative to promptly apply the available security updates.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:46 pm, Mai 17, 2025
Wetter-Symbol 19°C
L: 17° | H: 21°
klarer Himmel
Luftfeuchtigkeit: 50 %
Druck: 1022 mb
Wind: 6 mph N
Windböe: 8 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:05 am
Sonnenuntergang: 8:48 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 21°°C 0 mm 0% 9 mph 64 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
9° | 16°°C 0 mm 0% 9 mph 83 % 1022 mb 0 mm/h
Mo. Mai 19 10:00 pm
Wetter-Symbol
11° | 19°°C 0.2 mm 20% 13 mph 78 % 1022 mb 0 mm/h
Di. Mai 20 10:00 pm
Wetter-Symbol
9° | 21°°C 0.35 mm 35% 9 mph 81 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
11° | 20°°C 0.09 mm 9% 11 mph 79 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 7 mph 50 % 1021 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 9 mph 49 % 1021 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
14° | 15°°C 0 mm 0% 7 mph 64 % 1022 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 5 mph 76 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 83 % 1021 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 8 mph 82 % 1021 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 69 % 1022 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 7 mph 52 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,194.35
-0.75%
Ethereum(ETH)
€2,209.42
-5.37%
Fesseln(USDT)
€0.90
-0.01%
XRP(XRP)
€2.10
-3.99%
Solana(SOL)
€149.47
-3.62%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.191645
-6.09%
Shiba Inu(SHIB)
€0.000013
-6.22%
Pepe(PEPE)
€0.000011
-9.41%
Peanut das Eichhörnchen(PNUT)
€0.265459
-15.90%
Nach oben scrollen