logo

Critical Vulnerability in Progress MOVEit Transfer:…

ID: a8d9cced-e044-5b2f-a8d9-83b2c44d2a6b

STIX ID: report--a8d9cced-e044-5b2f-a8d9-83b2c44d2a6b

Feed Name: TrustedSec blog

Threat Score
85/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

Progress MOVEit Transfer (CVE-2023-34362) suffers a SQL injection vulnerability that has been actively exploited to install an ASPX webshell/backdoor (notably human2.aspx) enabling unauthenticated listing and exfiltration of files and insertion of an administrative backdoor account; the report provides backdoor behavior, IOCs (filenames, HTTP headers, SHA256 hashes, IPs), detection steps, response recommendations (forensic investigation, rebuild from trusted backups) and vendor mitigations (fixed versions, block HTTP/S to MOVEit, rotate Azure storage keys).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.