On 1 June 2023 the US Cybersecurity and Infrastructure Security Agency and the FBI published a joint advisory on the exploitation of CVE-2023-34362, a SQL injection vulnerability in Progress Software’s MOVEit Transfer. The advisory attributes the campaign to the group tracked as CL0P, also reported as TA505.
The vulnerability is unauthenticated. An attacker reaching an internet-facing MOVEit Transfer web application could query the database behind it without holding any credential at all.
A Web Shell, Then The Database
Per the joint advisory, exploitation installed a web shell that researchers named LEMURLOOT on internet-facing MOVEit Transfer applications, which was then used to steal data from the underlying MOVEit Transfer databases. Reporting places the earliest observed exploitation attempts at 27 May 2023, several days before the vendor advisory.
That gap is the part worth holding on to. The patch date is not the exposure date, and for a zero-day the window that matters closed before most defenders knew it was open.
Why A File Transfer Product Is The Worst Place For This
Managed file transfer exists to move regulated material between organisations: payroll files, claims data, member records, whatever two parties cannot email. The product is bought precisely because the data is sensitive. That concentration is the reason a single flaw in it reached organisations across sectors and jurisdictions that shared nothing except a supplier.
This desk has filed the same shape repeatedly since — at 25-0903, where managed file transfer appears four times in one year, and at 25-1110, where an Oracle E-Business Suite campaign produced a victim list with no common industry. The corpus now records the pattern often enough to state it plainly: where a product sits between organisations, its vulnerabilities are not distributed like its customers, they are distributed like its deployments.
What The Advisory Does Not Establish
The joint advisory is a technical and mitigation document. It does not put a number on affected organisations or affected people, and this file does not carry one. Totals circulated widely in later reporting, assembled by researchers counting leak-site listings and notification filings; those counts are downstream of an attacker’s publication decisions and of fifty different notification regimes, and the desk does not treat them as a measurement.
Built on the CISA/FBI joint advisory AA23-158A and Progress Software’s own critical vulnerability notice, both retrieved and read by this desk. The attribution to CL0P is the advisory’s, reported as such. The 27 May first-exploitation date is from secondary technical reporting and is stated as reported rather than as established. No figure for affected organisations or individuals is asserted: the primary documents do not contain one, and the widely circulated totals are aggregations of leak-site listings and notification filings rather than a count anyone is in a position to make. No indicators are reproduced. Graded high on the vulnerability, the exploitation and the attribution; the scope remains open. Corrections: corrections@forensicpost.com.
- #StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit VulnerabilityCybersecurity and Infrastructure Security Agency
- MOVEit Transfer Critical Vulnerability (May 2023) (CVE-2023-34362)Progress Software