MOVEit Transfer Zero-Day: What We Know So Far
ID: a8644470-4d65-57d8-9503-d3879fbd227b
STIX ID: report--a8644470-4d65-57d8-9503-d3879fbd227b
Feed Name: ReliaQuest Blog
Threat Score
## Executive Summary ReliaQuest reports a critical SQL injection vulnerability (CVE-2023-34362) in MOVEit Transfer discovered May 31, 2023 and observed exploited in the wild since at least May 27, 2023; successful exploitation can allow SQL execution, privilege escalation, and data exfiltration across multiple affected MOVEit versions, and the advisory provides immediate mitigations (disable HTTP/HTTPS, apply vendor patches, backup systems) and detection/hunting actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
