CVE-2023-34362 RCE vulnerability in MOVEit Transfer exploited in the wild: everything you need to know
ID: 218c2093-1fe2-5406-8774-c0dbcf53dc3c
STIX ID: report--218c2093-1fe2-5406-8774-c0dbcf53dc3c
Feed Name: Wiz Blog
Progress disclosed multiple critical vulnerabilities in MOVEit Transfer (including CVE-2023-34362 and later CVEs) that allow unauthenticated SQL injection/RCE against the application; these flaws were actively exploited in the wild, with the Cl0p ransomware group claiming responsibility and multiple organizations publicly disclosing compromise and data exfiltration. Progress published fixed versions and guidance; the report recommends immediate patching, restricting public HTTP access, rotating compromised cloud/database credentials, and using vendor advisories and threat center queries to identify exposed instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
