Recent months have witnessed a surge in hacker activity targeting inadequately maintained devices vulnerable to older security flaws from 2022 and 2023.
According to the threat monitoring platform GreyNoise, there has been a marked increase in attempts by cybercriminals to exploit CVE-2022-47945 and CVE-2023-49103, which affect the ThinkPHP Framework and the open-source file-sharing solution ownCloud.
Both vulnerabilities carry critical severity ratings and can be exploited to execute arbitrary operating system commands or to extract sensitive data, such as administrator credentials and mail server information.
The first, CVE-2022-47945, involves a local file inclusion (LFI) problem in the ThinkPHP Framework, impacting versions prior to 6.0.14. An attacker can remotely exploit this vulnerability in environments where the language pack feature is enabled.
Akamai reported that Chinese threat actors have been actively exploiting this flaw since October 2023 for limited-scope operations. Recently, GreyNoise noted that 572 unique IP addresses have attempted to exploit CVE-2022-47945, with activity on the rise.
Source: GreyNoise
The second vulnerability, CVE-2023-49103, affects the widely used ownCloud software due to its reliance on a vulnerable third-party library. After its disclosure in November 2023, hackers quickly began exploiting this flaw to obtain sensitive information from unpatched systems.
Despite over two years since the vendor’s last security update, many instances of ownCloud remain unpatched and vulnerable. GreyNoise has recently noted an uptick in attacks originating from 484 unique IPs targeting this flaw.
Source: GreyNoise
To mitigate these risks, users are strongly advised to upgrade to ThinkPHP version 6.0.14 or later, and ownCloud GraphAPI to version 0.3.1 or newer. Vulnerable systems should also be taken offline or secured behind a firewall to minimize exposure.
Vocabulary List:
- Vulnerability /ˌvʌl.nəˈbɪl.ɪ.ti/ (noun): The quality of being open to damage or attack.
- Exploitation /ˌɛk.splɔɪˈteɪ.ʃən/ (noun): The action of making full use of and benefiting from resources.
- Severity /səˈver.ɪ.ti/ (noun): The condition of being very bad or serious.
- Mitigate /ˈmɪt.ɪ.ɡeɪt/ (verb): To make less severe serious or painful.
- Extraction /ɪkˈstræk.ʃən/ (noun): The action of taking out something especially using effort or force.
- Unpatched /ʌnˈpætʃt/ (adjective): Referring to software or a system that has not been updated with security fixes.
How much do you know?
