Security News > 2022 > October > ConnectWise fixes RCE bug exposing thousands of servers to attacks
ConnectWise has released security updates to address a critical vulnerability in the ConnectWise Recover and R1Soft Server Backup Manager secure backup solutions.
Affected software versions include ConnectWise Recover or earlier and R1Soft SBM v6.16.3 or earlier.
Discovered by Code White security researcher Florian Hauser and expanded by Huntress Labs security researchers John Hammond and Caleb Stewart, the vulnerability can be used to "Push ransomware" through thousands of R1Soft servers exposed on the Internet, according to Huntress Labs CEO Kyle Hanslovan.
According to a Shodan scan, more than 4,800 Internet-exposed R1Soft servers are likely exposed to attacks if they haven't been patched since ConnectWise has released patches for this RCE bug.
"Affected ConnectWise Recover SBMs have automatically been updated to the latest version of Recover," ConnectWise said.
An end-of-the-week release also makes it harder to patch any vulnerable servers before the weekend, exposing more systems to attack for at least a few days.
News URL
Related news
- Oracle WebLogic Server OS Command Injection Flaw Under Active Attack (source)
- TellYouThePass ransomware exploits recent PHP RCE flaw to breach servers (source)
- Critical RCE flaws in vCenter Server fixed (CVE-2024-37079, CVE-2024-37080) (source)
- Week in review: CDK Global cyberattack, critical vCenter Server RCE fixed (source)
- Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks (source)
- New regreSSHion OpenSSH RCE bug gives root on Linux servers (source)
- Hackers attack HFS servers to drop malware and Monero miners (source)
- RCE bug in widely used Ghostscript library now exploited in attacks (source)
- CISA warns critical Geoserver GeoTools RCE flaw is exploited in attacks (source)
- Progress warns of critical RCE bug in Telerik Report Server (source)