EXPOSURES › CVE-2023-34362
CVE-2023-34362
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated SQL injection flaw in Progress MOVEit Transfer allowed attackers to alter or delete database elements, leading to a ransomware-linked breach.
Progress MOVEit Transfer contained a SQL injection vulnerability enabling unauthenticated attackers to execute arbitrary SQL commands, altering or deleting database elements. This critical flaw was actively exploited in the wild and linked to ransomware attacks, causing mass data breaches. DIB organizations must ensure MOVEit is patched and monitored, as unpatched CVEs are a primary vector for ransomware and data exfiltration.
Shame score — A critical, unpatched SQL injection flaw was actively exploited in the wild to cause ransomware-linked data breaches, demonstrating severe negligence in patch management and security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.