Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks
ID: 148aa261-3bbd-5714-8982-c5640b9fd642
STIX ID: report--148aa261-3bbd-5714-8982-c5640b9fd642
Feed Name: Bleeping Computer
Hackers are actively exploiting an undocumented cryptographic flaw in Gladinet CentreStack and Triofox where hardcoded AES keys and IVs in GladCtrl64.dll allow attackers to decrypt or forge Access Tickets; forged tickets were used to retrieve web.config and the machineKey, enabling ViewState deserialization remote code execution. Huntress observed exploitation against at least nine organizations, Gladinet released patches and IoCs, and defenders are advised to update, rotate machine keys, and scan for the provided indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
