Skip to content

MOVEit Transfer (CVE-2023-34362)

CVE-2023-34362CWE-89OWASP A03:2021CVSS 9.8Updated October 1, 20262 min read

CVE-2023-34362 is a SQL injection in Progress MOVEit Transfer that let an attacker read files and user records without credentials and leave a web shell behind. The Cl0p group exploited it days before any advisory existed, and used it not to encrypt anything but to steal data and extort the organisations it belonged to.

Affected
MOVEit Transfer before 2021.0.6, 2021.1.4, 2022.0.4, 2022.1.5 and 2023.0.1
Patched in
MOVEit Transfer 2023.0.1 and the simultaneous patches for older branches
Actively exploited
yes

In late May 2023 the extortion group Cl0p began stealing files at scale from organisations running MOVEit Transfer. Vendor Progress did not publish its advisory until 31 May. The preparation went back much further: Kroll found traces in customer logs suggesting Cl0p was already testing the attack in July 2021. What came next was one of the broadest data theft campaigns to date.

What is CVE-2023-34362

MOVEit Transfer is software organisations use to exchange files securely. Its web interface carried a SQL injection: input from an unauthenticated visitor landed straight in a database query. With it an attacker could read and alter the database, obtain a forged access token with system administrator rights, and from there get the server to run code.

Why a SQL injection weighed so heavily here

In most applications a SQL injection yields data. Here the database held precisely what the software existed to protect: the references to every file being exchanged. An attacker reading the database was reading the organisation’s entire file exchange.

A second stage sat on top of that. The forged sysadmin token gave the attacker access to the MOVEit API. Through the SQL injection they then slipped a crafted serialised object into the database. When the application later deserialised it, turning it back into a live object without any checks, the attacker’s code ran. That turned the attack into remote code execution. Only then did Cl0p install the web shell that became the hallmark of the campaign: human2.aspx, named after the legitimate human.aspx and tracked as LEMURLOOT, which it used to pull data out of the database.

The chain behind your chain

Organisations that never used MOVEit were hit anyway. Payroll processors, pension administrators and healthcare back offices used it to exchange files with their clients, so the stolen records often belonged to organisations that had never seen the software. That makes this an instructive case in supplier risk as much as in injection.

What to do now

  • If you run MOVEit Transfer, make sure it is on a version Progress still supports, with every current patch applied, and check whether unfamiliar files such as human2.aspx have appeared in the web directory since May 2023.
  • Do not put file transfer platforms directly on the internet without reason. An access layer in front of them shrinks the attack surface considerably.
  • Ask your suppliers which platforms they use to exchange data with you, and how they patch them.
  • Have internet-facing applications tested regularly. An injection like this one is standard ground in a penetration test.

Sources

Frequently asked questions

Why did this one become so notorious?

Not for the technique but for the scale. MOVEit is used to exchange files between organisations, so one compromised server often leaked the records of dozens of that organisation's clients at once.

Was ransomware involved?

Nothing was encrypted. Cl0p only stole data and threatened to publish it. That is now a common model: extortion without the overhead of encryption.

Would patching have prevented it?

Not in the first wave. The attack was already running before Progress published its advisory. Patching quickly did limit the damage of the weeks that followed.

Related articles

Press / to search · Esc