SharePoint Vulnerability: Severity 9.8 Global Exploit
Table of Contents
SharePoint, a cornerstone of collaboration and document management for countless organizations, recently faced a significant security threat stemming from a critical vulnerability related to data serialization. This isn’t a new issue – the underlying principles have been exploited before – but a recent wave of attacks in July 2023 demonstrated a sophisticated exploitation technique, highlighting the ongoing risk. This article provides a thorough guide to understanding the vulnerability, its implications, and the steps organizations must take to protect their systems.
what is Serialization and Why Does It Matter?
At its core, the vulnerability revolves around a process called serialization. Serialization is the conversion of data structures or object states into a format that can be stored (e.g., in a database or file) or transmitted (e.g., over a network) and then reconstructed later. Think of it like taking a complex Lego creation, carefully documenting each brick’s position, and then shipping the instructions to someone else who can rebuild the exact same structure.
In the context of web applications like SharePoint, serialization is crucial for maintaining state – remembering user sessions, form data, and other dynamic facts. However, if not handled securely, deserialization (the reverse process of reconstructing the data) can become a hazardous entry point for attackers.
The danger lies in what happens when an submission blindly trusts the serialized data it receives. If an attacker can manipulate the serialized data to include malicious code, the deserialization process can execute that code on the server, leading to remote code execution (RCE). This is precisely what happened in the recent SharePoint attacks.
The specific vulnerability exploited in the July 2023 attacks isn’t entirely new. A similar vulnerability in SharePoint (CVE-2021-28474) was patched by Microsoft in 2021. This earlier vulnerability allowed attackers to abuse parsing logic to inject objects into pages. SharePoint utilizes ASP.NET ViewState objects, which rely on a signing key – the ValidationKey – stored in the server’s configuration. The 2021 vulnerability allowed attackers to cause SharePoint to deserialize arbitrary objects and execute embedded commands.
Though, exploiting this earlier vulnerability required access to the server’s secret ValidationKey to generate a valid signature. This presented a significant hurdle for attackers.
The recent attacks bypassed this limitation through a clever technique. Researchers at eye Security discovered that attackers were able to extract the ValidationKey directly from compromised SharePoint servers. This key is essential for generating valid __VIEWSTATE payloads, and gaining access to it effectively turns any authenticated SharePoint request into a remote code execution chance.
How the July 2023 Attacks Unfolded
On July 18th and 19th, 2023, eye Security researchers reported identifying “dozens of systems actively compromised” during two waves of attacks. These systems, globally distributed, were compromised using the exploited vulnerability and infected with a webshell-based backdoor called ToolShell.
What made this attack unique was the nature of the webshell. Unlike typical webshells that offer interactive command execution, ToolShell operated differently. According to Eye Security’s report, “There were no interactive commands, reverse shells, or command-and-control logic. Instead, the page invoked internal .NET methods to read the SharePoint server’s MachineKey configuration, including the validationkey.”
Once the ValidationKey was obtained, attackers could craft malicious payloads that bypassed security checks and allowed them to execute code within the SharePoint habitat. This enabled them to expand their reach within the network, potentially accessing sensitive data and compromising other systems.
The Impact of a Triumphant Exploit
A successful exploit of this vulnerability can have devastating consequences:
Remote Code Execution (RCE): Attackers gain the ability to execute arbitrary code on the SharePoint server, effectively taking control of the system.
Data Breach: Sensitive data stored within SharePoint, including confidential documents, customer information, and intellectual property, can be stolen. Lateral Movement: Attackers can use the compromised SharePoint server as a launching pad to move laterally within the network,compromising other systems and escalating their privileges.
System Disruption: Attackers can disrupt sharepoint services, causing downtime and impacting business operations.
Credential Theft: As highlighted in the initial reports, attackers can steal authentication credentials, granting them wide access to various sensitive resources.
Protecting your SharePoint environment requires a multi-layered approach. Here’s a breakdown of essential mitigation strategies:
Apply Security Updates: This is the most critical step. Ensure you have applied all available security updates from Microsoft, including the patch released for CVE-2021-2847
