Target Industry
Indiscriminate, opportunistic targeting.
Overview
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding the active exploitation of critical vulnerabilities in VMware vCenter Server and Progress Kemp LoadMaster systems. Kemp LoadMaster is a high-performance application delivery controller and load balancer that ensures the availability, scalability, performance, and security of business-critical applications and websites. The vulnerabilities, tracked as CVE-2024-1212 and CVE-2024-38813, have CVSS scores of 10.0 and 7.8, respectively. CVE-2024-1212 was first reported in February 2024, while CVE-2024-38813 was reported in September 2024. Broadcom released initial patches for both vulnerabilities in September 2024, followed by updated patches in October 2024. It is recommended that the patches for the Kemp LoadMaster vulnerability be applied by 9th December 2024.
Impact
CVE-2024-1212 allows threat actors to execute arbitrary system commands (OS Command injection) and escalate privileges, potentially compromising entire systems. CVE-2024-38813 allows threat actors with network access to escalate privileges to root by sending specially crafted network packets.
Exploitation
Using CVE-2024-1212 remote threat actors can exploit the LoadMaster management interface without authentication. The vulnerability has different areas which are open to be exploited; these are:
- Command execution due to inadequate validation and sanitisation of user inputs, especially in the “REMOTE_USER” and “REMOTE_PASS” environment variables. The vulnerability enables command injection.
- By creating specific request paths and parameters, threat actors can circumvent disabled API restrictions, enabling access to critical functions even when the REST API is turned off.
- As there is insufficient validation and sanitisation in the LoadMaster, the threat actor has utilised user-controllable input to facilitate the execution of arbitrary commands on the system.
CVE-2024-38813 enables threat actors to gain root-level privileges and could be exploited as listed below:
- Unauthorised access to the vCenter Server to have network access
- Network packets are crafted enabling the exploit to happen
- The threat actor uses a low-level user account to escalate to root giving them full system access.
Containment, Mitigations & Remediations
To remediate CVE-2024-1212, update to the latest version by applying the security patches provided by Progress Kemp. As a temporary measure, restrict access to the LoadMaster management interface and ensure it is not exposed to untrusted networks. To remediate CVE-2024-38813, install the latest updates released by VMware to address this privilege escalation vulnerability. Additionally, ensure that network access to the vCenter Server is properly secured to prevent unauthorised access.
Indicators of Compromise
To detect potential exploitation of CVE-2024-1212, monitor for unusual HTTP GET requests to the LoadMaster management interface, especially those targeting /access/set with parameters like param=enableapi and value=1. Additionally, check for suspicious authorisation headers containing values such as Basic Jz, Basic c7, Basic nO, or Basic ‘;. For CVE-2024-38813, monitor network traffic for customised packets sent to the vCenter Server, which may indicate an attempt to exploit the privilege escalation vulnerability. Also, look for signs of unauthorised privilege escalation, such as unexpected root access or changes in user privileges.
Threat Landscape
Although Progress software has an extremely low number of users, the vulnerabilities reported are critical to companies. They pose a real threat of networks being fully compromised and it is important to have an awareness of these vulnerabilities.
Threat Group
The specific threat group behind this has not been publicly identified at the time of writing.
TTPs
- TA0004 – Privilege Escalation
- T1623 – Command and Scripting Interpreter
- T1078 – Valid Accounts
Further Information
https://www.theregister.com/2024/11/18/vmware_vcenter_rce_exploited/?td=rt-3a https://nvd.nist.gov/vuln/detail/CVE-2024-38813 https://rhinosecuritylabs.com/research/cve-2024-1212unauthenticated-command-injection-in-progress-kemp-loadmaster/ https://thehackernews.com/2024/11/cisa-alert-active-exploitation-of.html https://nvd.nist.gov/vuln/detail/CVE-2024-1212 












