On March 31st, a researcher released a proof-of-concept (POC) attack that could remotely upload a web shell to a web server running Spring Framework, revealing a major new remote code execution vulnerability. This poses a significant danger to enterprises since a vulnerability like this might allow an attacker to seize control of the affected server.
Malicious scripts known as web shells allow threat actors to hijack web servers and execute further assaults. Threat actors can infiltrate a system or network before installing a web shell. They can utilize a web shell as a permanent backdoor into the compromised systems from this point forward.
Spring Framework versions prior to 5.3.18 are vulnerable to remote code execution.
Execute Operator’s CVE-2022-22965 TTP on each host running Spring Framework in your environment to test if you are vulnerable.
The TTP is configured to upload a webshell to the machine, run a command, and check for a specific output. If the output is successful then it'll delete the web shell completely, removing the web shell artifact from your system.
Upgrade Spring Framework to version 5.3.18 or above. Spring has puboished a security advisory with instructions for patching and mitigating this vulnerability.
Thanks for reading our latest TTP Tuesday release! Please subscribe and reach out with any feedback. We love to hear from our community!
There are several ways to follow us and learn more about Prelude and our team members:
Download Prelude Operator: https://www.prelude.org/download/current
See the latest kill chain and TTP Releases: https://chains.prelude.org/
See our open-source repositories: https://github.com/preludeorg
Discord: https://discord.gg/gzUv4XNquu
Reddit: https://www.reddit.com/r/preludeorg/
Twitter: https://twitter.com/preludeorg
Listen to our Podcast: https://anchor.fm/preludeorg
Read our blog: https://feed.prelude.org
Watch our live streams: https://www.twitch.tv/preludeorg
Watch our pre-recorded content: https://www.youtube.com/c/preludeorg
David: privateducky
Alex: khyberspache
Kris: Xanthonus
Octavia: VVX7
Bart: BartimusPrimed