Security News > 2021 > April > Pulse Secure Zero-Day Flaw Actively Exploited in Attacks

Pulse Secure Zero-Day Flaw Actively Exploited in Attacks
2021-04-20 21:23

Multiple threat actors are actively engaged in the targeting of four vulnerabilities in Pulse Secure VPN appliances, including a zero-day identified this month that won't be patched until next month.

Tracked as CVE-2021-22893 and discovered in April 2021, the fourth vulnerability won't receive a patch until early May, but Pulse Secure says that it has already provided mitigations to a very limited number of customers affected.

Rated critical severity, the issue is described as an authentication bypass that could allow unauthenticated attackers to execute arbitrary files remotely on Pulse Connect Secure gateways.

According to FireEye, there are 12 malware families that are currently actively engaged in the exploitation of vulnerable Pulse Secure VPN devices, yet they aren't necessarily related to one another, which suggests that multiple threat actors are responsible "For the creation and deployment of these various code families."

Leveraging harvested credentials from Pulse Secure VPN login flows, one threat actor was able to move laterally into the compromised networks and then employ modified Pulse Secure binaries and scripts on the VPN to maintain persistent access to the environment.

Pulse Secure has released an integrity checker tool to help customers assess any possible impact from the aforementioned vulnerabilities.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/4Ji8G5gfF30/pulse-secure-zero-day-flaw-actively-exploited-attacks

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-04-23 CVE-2021-22893 Use After Free vulnerability in Ivanti Connect Secure 9.0/9.1
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway.
network
low complexity
ivanti CWE-416
critical
10.0