Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Apache ActiveMQ Vulnerability Exploited as Zero-Day

The recently patched Apache ActiveMQ vulnerability tracked as CVE-2023-46604 has been exploited as a zero-day since at least October 10.

Malicious exploitation of an Apache ActiveMQ vulnerability tracked as CVE-2023-46604 started at least two weeks prior to patches being released, according to managed detection and response firm Huntress.  

Apache ActiveMQ is a popular open source, multi-protocol message broker, and there are still thousands of internet-exposed instances that are vulnerable to attacks exploiting CVE-2023-46604, which can be leveraged for remote code execution. 

A patch for the vulnerability was committed to the source code on October 24 and the existence of the security flaw was made public on October 27. 

Rapid7 started seeing exploitation attempts on the same day, with attackers apparently trying to deliver HelloKitty ransomware, whose source code was leaked in early October.

However, Huntress has found evidence that CVE-2023-46604 was exploited as a zero-day since at least October 10.

“At the time that the events were investigated, Huntress analysts found no additional, subsequent malicious activity on the endpoint, indicating that the infection process did not succeed,” the company said in a blog post on Thursday. 

Advertisement. Scroll to continue reading.

Technical details and proof-of-concept (PoC) code for CVE-2023-46604 are publicly available. In addition, exploitation of the vulnerability is trivial and there is even a Metasploit module that automates exploitation. 

That’s why it’s important that users update ActiveMQ as soon as possible to versions 5.15.16, 5.16.7, 5.17.6 or 5.18.3, which patch the flaw.

Indicators of compromise (IoCs) are available from both Rapid7 and Huntress

This is not the first Apache ActiveMQ vulnerability that has been exploited in the wild. The US cybersecurity agency CISA warned last year that CVE-2016-3088, which allows remote attackers to upload and execute arbitrary files, has also been leveraged for malicious purposes. 

Related: Companies Address Impact of Exploited Libwebp Vulnerability 

Related: Recently Patched TeamCity Vulnerability Exploited to Hack Servers

Related: Recent NetScaler Vulnerability Exploited as Zero-Day Since August

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

John Opala has joined Ralph Lauren as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.