Hackers exploit KerioControl firewall flaw to steal admin CSRF tokens

Teilen:

Hackers are trying to exploit CVE-2024-52875, a critical CRLF injection vulnerability that leads to 1-click remote code execution (RCE) attacks in GFI KerioControl firewall product.

KerioControl is a network security solution designed for small and medium-sized businesses that combines firewall, VPN, bandwidth management, reporting and monitoring, traffic filtering, AV protection, and intrusion prevention.

On December 16, 2024, security researcher Egidio Romano (EgiX) published a detailed writeup on CVE-2024-52875, demonstrating how a seemingly low-severity HTTP response splitting problem could escalate to 1-click RCE.

The vulnerability, which impacts KerioControl versions 9.2.5 through 9.4.5, is due to improper sanitization of line feed (LF) characters in the ‘dest’ parameter, allowing HTTP header and response manipulation via injected payloads.

Malicious JavaScript injected into responses is executed on the victim’s browser, leading to the extraction of cookies or CSRF tokens.

An attacker could use the CSRF token of an authenticated admin user to upload a malicious .IMG file containing a root-level shell script, leveraging the Kerio upgrade functionality, which opens a reverse shell for the attacker.

Active exploitation

Yesterday, threat scanning platform Greynoise detected exploitation attempts targeting CVE-2024-52875 from four distinct IP addresses, possibly using the PoC exploit code presented by Romano.

The activity is marked as “malicious” by the threat monitoring platform, indicating that the exploitation attempts are attributed to threat actors rather than researchers probing systems.

Also yesterday, Censys reported 23,862 internet-exposed GFI KerioControl instances, although it is unclear how many of them are vulnerable to CVE-2024-52875 is unknown.

GFI Software on December 19, 2024, released version 9.4.5 Patch 1 for the KerioControl product, which addresses the vulnerability . Users are recommended to apply the fix as soon as possible.

If patching is not possible at the moment, admins should limit access to KerioControl’s web management interface to trusted IP addresses and disable public access to the ‘/admin’ and ‘/noauth’ pages via firewall rules.

Monitoring for exploitation attempts targeting the ‘dest’ parameters and configuring shorter session expiration times are also effective mitigations.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:16 am, Apr. 20, 2025
Wetter-Symbol 6°C
L: 5° | H: 7°
broken clouds
Luftfeuchtigkeit: 85 %
Druck: 1008 mb
Wind: 7 mph NNE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:53 am
Sonnenuntergang: 8:04 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
5° | 7°°C 0 mm 0% 10 mph 90 % 1008 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
8° | 16°°C 0.7 mm 70% 11 mph 94 % 1013 mb 0 mm/h
Di. Apr. 22 10:00 pm
Wetter-Symbol
7° | 15°°C 0.2 mm 20% 8 mph 83 % 1019 mb 0 mm/h
Mi. Apr. 23 10:00 pm
Wetter-Symbol
9° | 14°°C 1 mm 100% 15 mph 96 % 1018 mb 0 mm/h
Do. Apr. 24 10:00 pm
Wetter-Symbol
9° | 12°°C 0 mm 0% 8 mph 86 % 1025 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
6° | 7°°C 0 mm 0% 8 mph 84 % 1008 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
11° | 13°°C 0 mm 0% 10 mph 69 % 1007 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 10 mph 58 % 1007 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 7 mph 73 % 1007 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 6 mph 78 % 1007 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 4 mph 90 % 1007 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
8° | 8°°C 0 mm 0% 3 mph 92 % 1007 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
8° | 8°°C 0 mm 0% 1 mph 94 % 1007 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€74,918.15
0.41%
Ethereum(ETH)
€1,419.73
1.33%
Fesseln(USDT)
€0.88
0.01%
XRP(XRP)
€1.83
0.13%
Solana(SOL)
€124.11
2.41%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.139092
-0.41%
Shiba Inu(SHIB)
€0.000011
0.49%
Pepe(PEPE)
€0.000007
2.40%
Nach oben scrollen