Vulnerability record · CVE-2023-34362 · published 2 June 2023
CVE-2023-34362: Progress MOVEit Transfer SQL injection allows unauthenticated database access
Progress · Moveit Cloud
Progress MOVEit Transfer contains a SQL injection flaw in its web application that lets an unauthenticated attacker reach and manipulate the underlying database. It affects all versions before the five fixed releases listed, including older unsupported versions, and was exploited in the wild in May and June 2023. Because the flaw is remotely reachable without credentials, it is a high-value target for mass exploitation.
Description
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote SQL injection with CVSS 9.8, active in-the-wild exploitation, CISA KEV listing with ransomware use, and near-maximum EPSS probability make this an urgent patch-first issue.
What it is
Progress MOVEit Transfer contains a SQL injection flaw in its web application that lets an unauthenticated attacker reach and manipulate the underlying database. It affects all versions before the five fixed releases listed, including older unsupported versions, and was exploited in the wild in May and June 2023. Because the flaw is remotely reachable without credentials, it is a high-value target for mass exploitation.
Impact
An attacker can read database structure and contents and execute SQL statements that alter or delete database elements. In practice this gives full compromise of the MOVEit Transfer database and the data it holds.
Attack surface
Reachable over HTTP or HTTPS through the MOVEit Transfer web application; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Exploited in the wild in May and June 2023, listed in CISA KEV with a 2023-06-23 remediation due date and known ransomware campaign use, and EPSS 30-day probability is 0.99934 (99.97th percentile). Public exploit references are tagged Exploit.
What to do
- Apply the vendor updates immediately: MOVEit Transfer 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1).
- If patching cannot be done immediately, take the affected MOVEit Transfer web interface offline or restrict access to trusted networks until the update is applied.
- Follow the Progress vendor advisory for any additional remediation steps, including checking for and removing attacker-created database elements or web shells.
- Treat all data stored in or transferred through MOVEit Transfer as potentially exposed and review it for sensitive content.
- Monitor for and rotate credentials and secrets that were accessible to the MOVEit Transfer database or application.
Detection
- Review MOVEit Transfer web and application logs for anomalous SQL-related requests or unexpected HTTP/HTTPS activity against the web interface.
- Hunt for unexpected database objects, scheduled jobs, or files created in the MOVEit Transfer environment that are not part of normal operations.
- Monitor for outbound connections or data transfers from MOVEit Transfer hosts that deviate from baseline behavior.
- Check for indicators associated with Cl0p ransomware activity, which is documented as using this vulnerability.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-34362 to the Known Exploited Vulnerabilities catalog on 2 June 2023 as "Progress MOVEit Transfer SQL Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 23 June 2023.
Ransomware crews whose documented playbooks reference this CVE: