All vulnerabilities
CRITICALInfraexploited in the wildransomware

CVE-2023-34362

Progress MOVEit · Progress MOVEit Transfer

Summary

An unauthenticated SQL injection flaw in the MOVEit Transfer managed file transfer web application that lets an attacker access and manipulate the backend database. The Cl0p ransomware gang exploited it as a zero-day starting May 27, 2023, chaining it to deploy a LEMURLOOT web shell and exfiltrate stored files at scale. It became one of the largest mass data-theft events on record, with roughly 2,700 organizations and more than 84 million individuals affected, including Zellis, Siemens Energy, Schneider Electric, and numerous government entities.

References

Related vulnerabilities

All Infra →