SANS Stormcast Wednesday Mar 26th: XWiki Exploit; File Converter Correction; VMWare Vulnerability; Draytek Router Reboots; MMC Exploit Details;
Mar 26, 2025
auto_awesome
Discover the surge in exploit attempts targeting an XWiki vulnerability that allows command injection. Learn about the FBI's warning regarding unsafe online file converters. Follow the latest on a VMWare Tools flaw that could escalate user privileges within virtual machines. Hear about issues with Draytek routers stuck in a reboot loop and the advised fixes. Finally, get insights into the recent exploitation of a Microsoft Management Console vulnerability patched just days ago.
An increase in exploit attempts for the XWiki vulnerability indicates a rising threat, prompting users to urgently update their systems.
Recent VMware Tools updates address a significant authentication bypass issue, allowing attackers to escalate privileges in Windows virtual machines.
Deep dives
Vulnerability in XWiki Search Feature
A significant vulnerability in XWiki has been identified, affecting its search feature, which allows for remote code execution. This specific issue arises from how the search string undergoes rendering transformations, which can lead to malicious code being executed when a user searches for certain queries, like a groovy code snippet. Although the vulnerability is about a year old, it has recently come to attention due to instances detected in honeypots, suggesting targeted exploitation may be increasing. Users of XWiki are strongly advised to update their systems to mitigate this risk, as it poses a serious security concern despite being classified as an older vulnerability.
Updates on VMware and TreeTech Issues
Recent updates from VMware address an authentication bypass issue in VMware Tools, impacting Windows virtual machines, where normal user access may inadvertently lead to administrative privileges for attackers. This vulnerability has a CVSS score of 7.8, highlighting its potential severity. Additionally, TreeTech routers have been experiencing widespread reboot loops due to a firmware update issue, complicating user attempts to regain control of their devices. TreeTech suggests directly upgrading the firmware as a solution, although this can be challenging due to the rebooting behavior, requiring users to explore options like TFTP for updates.
1.
Exploring Recent Vulnerabilities and Cybersecurity Updates