Critical Vulnerability Disclosure: ConnectWise/R1Soft Server Backup Manager Remote Code Execution & Supply Chain Risks
ID: 3276de59-32b0-50ff-8e3e-32bf46a3f2b6
STIX ID: report--3276de59-32b0-50ff-8e3e-32bf46a3f2b6
Feed Name: Huntress Blog
Huntress researchers reproduced an authentication bypass in the ZK framework (CVE-2022-36537) present in ConnectWise R1Soft Server Backup Manager, developed a chained exploit that uploads a malicious JDBC driver to obtain root remote code execution, and demonstrated the ability to push LockBit 3.0 ransomware to downstream endpoints; ConnectWise released a patch (SBM v6.16.4) which Huntress validated, while research highlights thousands of potentially exposed instances and provides indicators and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
