The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added CVE-2022-36537 to its "Known Exploited Vulnerabilities Catalog" after threat actors began actively exploiting the remote code execution (RCE) flaw in attacks. CVE-2022-36537 is a high-severity (CVSS v3.1: 7.5) flaw impacting the ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1, enabling attackers to access sensitive information by sending a specially crafted POST request to the AuUploader component. "ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context," mentions CISA's description of the flaw. The flaw was discovered last year by Markus Wulftange and addressed by ZK on May 05, 2022, with version 9.6.2. ZK is an open-source Ajax Web app framework written in Java, enabling web developers to create graphical user interfaces for web applications with minimal effort and programming knowledge. The ZK framework is widely employed in projects of all types and sizes, so the flaw's impact is widespread and far-reaching. Notable examples of products using the ZK framework include ConnectWise Recover, version 2.9.7 and earlier, and ConnectWise R1SoftServer Backup Manager, version 6.16.3 and earlier. CISA set the deadline to apply the available security updates to March 20, 2023, giving federal agencies roughly three weeks to respond to the security risk and take proper action to secure their...
CISA warns of hackers exploiting ZK Java Framework RCE flaw
BleepingComputer
·Published Feb 28, 2023
·Updated
Affected Software
3 affected components
ZK Framework=9.6.1, =9.6.0.1, =9.5.1.3, =9.0.1.2, =8.6.4.1
ConnectWise Recover<=2.9.7
ConnectWise R1Soft Server Backup Manager<=6.16.3
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of a remote code execution flaw in the ZK Java Framework as warned by CISA.
2
What security implications are discussed in the article?
The article highlights the risks associated with the exploitation of CVE-2022-36537, which could allow attackers to execute malicious code on vulnerable systems.
3
What specific vulnerabilities are highlighted in the article?
The article emphasizes the remote code execution flaw identified as CVE-2022-36537.
4
What products or software are affected by the vulnerability mentioned?
The affected software includes the ZK Framework, ConnectWise Recover, and ConnectWise R1SoftServer Backup Manager.
5
Which versions of the affected software are vulnerable?
Vulnerable versions for ZK Framework range from 8.6.4.1 to 9.6.1, while ConnectWise Recover versions up to 2.9.7 and R1SoftServer Backup Manager versions up to 6.16.3 are affected.