Target Industry

Indiscriminate, opportunistic targeting. 

Overview 

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding the active exploitation of critical vulnerabilities in VMware vCenter Server and Progress Kemp LoadMaster systems. Kemp LoadMaster is a high-performance application delivery controller and load balancer that ensures the availability, scalability, performance, and security of business-critical applications and websites.   The vulnerabilities, tracked as CVE-2024-1212 and CVE-2024-38813, have CVSS scores of 10.0 and 7.8, respectively. CVE-2024-1212 was first reported in February 2024, while CVE-2024-38813 was reported in September 2024. Broadcom released initial patches for both vulnerabilities in September 2024, followed by updated patches in October 2024. It is recommended that the patches for the Kemp LoadMaster vulnerability be applied by 9th December 2024. 

Impact 

CVE-2024-1212 allows threat actors to execute arbitrary system commands (OS Command injection) and escalate privileges, potentially compromising entire systems. CVE-2024-38813 allows threat actors with network access to escalate privileges to root by sending specially crafted network packets. 

Exploitation 

Using CVE-2024-1212 remote threat actors can exploit the LoadMaster management interface without authentication. The vulnerability has different areas which are open to be exploited; these are: 

  • Command execution due to inadequate validation and sanitisation of user inputs, especially in the “REMOTE_USER” and “REMOTE_PASS” environment variables. The vulnerability enables command injection. 
  • By creating specific request paths and parameters, threat actors can circumvent disabled API restrictions, enabling access to critical functions even when the REST API is turned off. 
  • As there is insufficient validation and sanitisation in the LoadMaster, the threat actor has utilised user-controllable input to facilitate the execution of arbitrary commands on the system. 

CVE-2024-38813 enables threat actors to gain root-level privileges and could be exploited as listed below: 

  • Unauthorised access to the vCenter Server to have network access 
  • Network packets are crafted enabling the exploit to happen 
  • The threat actor uses a low-level user account to escalate to root giving them full system access.  

Containment, Mitigations & Remediations 

To remediate CVE-2024-1212, update to the latest version by applying the security patches provided by Progress Kemp. As a temporary measure, restrict access to the LoadMaster management interface and ensure it is not exposed to untrusted networks. To remediate CVE-2024-38813, install the latest updates released by VMware to address this privilege escalation vulnerability. Additionally, ensure that network access to the vCenter Server is properly secured to prevent unauthorised access. 

Indicators of Compromise 

To detect potential exploitation of CVE-2024-1212, monitor for unusual HTTP GET requests to the LoadMaster management interface, especially those targeting /access/set with parameters like param=enableapi and value=1. Additionally, check for suspicious authorisation headers containing values such as Basic Jz, Basic c7, Basic nO, or Basic ‘;.  For CVE-2024-38813, monitor network traffic for customised packets sent to the vCenter Server, which may indicate an attempt to exploit the privilege escalation vulnerability. Also, look for signs of unauthorised privilege escalation, such as unexpected root access or changes in user privileges. 

Threat Landscape 

Although Progress software has an extremely low number of users, the vulnerabilities reported are critical to companies. They pose a real threat of networks being fully compromised and it is important to have an awareness of these vulnerabilities. 

Threat Group 

The specific threat group behind this has not been publicly identified at the time of writing. 

TTPs 

  • TA0004 – Privilege Escalation 
  • T1623 – Command and Scripting Interpreter 
  • T1078 – Valid Accounts 

 Further Information 

https://www.theregister.com/2024/11/18/vmware_vcenter_rce_exploited/?td=rt-3a  https://nvd.nist.gov/vuln/detail/CVE-2024-38813  https://rhinosecuritylabs.com/research/cve-2024-1212unauthenticated-command-injection-in-progress-kemp-loadmaster/  https://thehackernews.com/2024/11/cisa-alert-active-exploitation-of.html  https://nvd.nist.gov/vuln/detail/CVE-2024-1212 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content