CVE-2024-7694
9.5 CISA KEVTeamT5 · ThreatSonar Anti-Ransomware
TeamT5 ThreatSonar Anti-Ransomware is vulnerable to an unrestricted file upload flaw that allows authenticated administrators to execute arbitrary system commands on the server.
Executive summary
A critical remote code execution vulnerability in TeamT5 ThreatSonar Anti-Ransomware is currently being exploited in the wild, necessitating immediate patching.
Vulnerability
The application fails to properly validate the content of uploaded files, allowing an attacker with administrator privileges on the product platform to upload malicious files. This unrestricted file upload (CWE-434) enables the execution of arbitrary system commands on the underlying server.
Business impact
This vulnerability carries a CVSS score of 9.5, reflecting its critical severity. Successful exploitation allows a remote attacker to achieve full system compromise, leading to total loss of confidentiality, integrity, and availability. Given the product's role as an anti-ransomware solution, a compromise could result in the total subversion of security controls, data exfiltration, or the deployment of secondary malicious payloads across the enterprise environment.
Remediation
Immediate Action: Update TeamT5 ThreatSonar Anti-Ransomware to version 3.5.0 or later, or apply the provided Hotfix-20240715 immediately.
Proactive Monitoring: Monitor server logs for suspicious file upload activity or unauthorized execution of system commands, particularly those originating from administrative accounts.
Compensating Controls: Ensure strict access control lists are in place for the administrative interface and utilize a Web Application Firewall (WAF) to filter for malicious file extensions or signatures, although these should be viewed only as temporary measures.
Exploitation status
Public Exploit Available: Yes, public proof-of-concept material exists.
Analyst recommendation
Due to the confirmed active exploitation and the critical nature of the flaw, organizations must prioritize the application of the vendor-provided patch or hotfix. Failure to remediate this vulnerability exposes the environment to significant risk of total system takeover. Administrators should verify the update status across all instances immediately to ensure protection against ongoing exploitation campaigns.