CVE-2024-7694

9.5 CISA KEV

TeamT5 · ThreatSonar Anti-Ransomware

TeamT5 ThreatSonar Anti-Ransomware is vulnerable to an unrestricted file upload flaw that allows authenticated administrators to execute arbitrary system commands on the server.

Executive summary

A critical remote code execution vulnerability in TeamT5 ThreatSonar Anti-Ransomware is currently being exploited in the wild, necessitating immediate patching.

Vulnerability

The application fails to properly validate the content of uploaded files, allowing an attacker with administrator privileges on the product platform to upload malicious files. This unrestricted file upload (CWE-434) enables the execution of arbitrary system commands on the underlying server.

Business impact

This vulnerability carries a CVSS score of 9.5, reflecting its critical severity. Successful exploitation allows a remote attacker to achieve full system compromise, leading to total loss of confidentiality, integrity, and availability. Given the product's role as an anti-ransomware solution, a compromise could result in the total subversion of security controls, data exfiltration, or the deployment of secondary malicious payloads across the enterprise environment.

Remediation

Immediate Action: Update TeamT5 ThreatSonar Anti-Ransomware to version 3.5.0 or later, or apply the provided Hotfix-20240715 immediately.

Proactive Monitoring: Monitor server logs for suspicious file upload activity or unauthorized execution of system commands, particularly those originating from administrative accounts.

Compensating Controls: Ensure strict access control lists are in place for the administrative interface and utilize a Web Application Firewall (WAF) to filter for malicious file extensions or signatures, although these should be viewed only as temporary measures.

Exploitation status

Public Exploit Available: Yes, public proof-of-concept material exists.

Analyst recommendation

Due to the confirmed active exploitation and the critical nature of the flaw, organizations must prioritize the application of the vendor-provided patch or hotfix. Failure to remediate this vulnerability exposes the environment to significant risk of total system takeover. Administrators should verify the update status across all instances immediately to ensure protection against ongoing exploitation campaigns.

More TeamT5 CVEs

Sources