Critical RCE Vulnerability
ID: 6df5733c-ed5e-5b46-84c0-78aa2c8e3218
STIX ID: report--6df5733c-ed5e-5b46-84c0-78aa2c8e3218
Feed Name: Arctic Wolf Blog
Threat Score
Apache published an advisory for CVE-2023-46604, a critical unauthenticated remote code execution vulnerability in ActiveMQ (CVSS 10.0). Arctic Wolf observed active exploitation of this flaw being used to deploy the TellYouThePass ransomware, and a public proof-of-concept is available; the advisory strongly recommends upgrading ActiveMQ to fixed versions and monitoring vendor patches for bundled instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
