Cyber999 Advisories

4 August 2024     Advisory

MA-1112.082024: MyCERT Advisory - High Severity vulnerability in Progress MOVEit Transfer


1.0 Introduction

Recently, Progress Software identified and patched a vulnerability (CVE-2024-6576) in Progress MOVEit Transfer which can lead to Privilege Escalation.


2.0 Impact

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead an attacker to Privilege Escalation.


3.0 Affected Products

  • Progress MOVEit Transfer (SFTP Module) - CVE-2024-6576: This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before 2023.1.7, from 2024.0.0 before 2024.0.3.


4.0 Recommendations

NOTICE: All MOVEit Transfer customers must take action and apply the patch to address the June 2024 vulnerability discovered in MOVEit Transfer.

CyberSecurity Malaysia urges users and organizations to review the MOVEit Transfer Advisory, follow the mitigation steps, apply the necessary updates, and hunt for any malicious activity.

Kindly refer to the URL for more information:

https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-July-2024-CVE-2024-6576

Generally, we advise users of this device to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.


For further enquiries, please contact Cyber999 through the following channels:


E-mail: cyber999[at]cybersecurity.my 

Phone: 1-300-88-2999 (monitored during business hours)  

Mobile: +60 19 2665850 (24x7 call incident reporting) 

Business Hours: Mon - Fri 08:30 -17:30 MYT 

Web: https://www.mycert.org.my 


5.0 References

logo
CyberSecurity Malaysia is the national cyber security specialist agency under the purview of the Ministry of Digital (KD)
 
Contact Us

  • CyberSecurity Malaysia,
    Level 7 Tower 1, Menara Cyber Axis, Jalan Impact,
    63000 Cyberjaya, Selangor Darul Ehsan, Malaysia.

  • enquiry@cybersecurity.my

  • +603 - 8800 7999

  • +603 - 8008 7000

TOP
ASK Byte
Chatbot Portal

Hi, I am ASK Byte. Please submit your questions about the portal and I will try to get answers from online knowledge stores.

Hi, Saya Admin Chatbot. Saya sedia chat dengan anda secara terus. Bagaimana saya boleh membantu anda?

Click the button below to interact with the CSM chatbot

Proceed