{"id":460,"date":"2021-03-02T05:33:47","date_gmt":"2021-03-02T05:33:47","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=460"},"modified":"2023-02-07T09:03:50","modified_gmt":"2023-02-07T09:03:50","slug":"exploit-win32-cve-2020-14882","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2021\/03\/02\/exploit-win32-cve-2020-14882\/","title":{"rendered":"Exploit.Win32.CVE-2020-14882"},"content":{"rendered":"<h2>General explanation<\/h2>\n<p><strong>Type<\/strong>: Vulnerability<\/p>\n<p><strong>Vulnerability platform:<\/strong> Oracle WebLogic Server<\/p>\n<p><strong>Vulnerability versions:<\/strong> 10.3.6.0.0- 14.1.1.0.0<\/p>\n<p><strong>The date of representing<\/strong> <strong>o<\/strong>f <strong>the patch by Microsoft:<\/strong> October 2020<\/p>\n<p><strong>Vulnerability module:<\/strong> Console Component<\/p>\n<p><strong>Vulnerability type:<\/strong> Unauthenticated Remote Code Execution<\/p>\n<p><strong>Degree of destruction:<\/strong> high<\/p>\n<p><strong>Used Malware:<\/strong><\/p>\n<ul>\n<li>Miner.Win64.CoinMiner.a<\/li>\n<li>Trojan.Win32.DarkIRC.Ss1<\/li>\n<\/ul>\n<h3>What is Vulnerability?<\/h3>\n<p>In computer security, Vulnerability is a defect inside a platform that can be seduced by an intruder or malware and provide unauthorized access to the computer system. Vulnerabilities allow the intruders to execute instructions, access system memory, install malware and steal information, destruct and change important information of organizations and individuals.<\/p>\n<h3>What is\u00a0CVE-2020-14882 vulnerability?<\/h3>\n<p>This vulnerability has a very high degree of danger (CVSS 9.8) and it is inside the component of the Oracle Weblogic Server software console. The intruder can use this vulnerability to have remote code access to this server by HTTP protocol and port 7001 which belongs to Weblogic Server and run its desired instructions.<\/p>\n<p>The intruder performs its malicious actions and only sends an HTTP request to this server which consists of malicious codes and needs no authentication in the Weblogic Server. The destructive codes for accessing an infected server can consist of executing a process such as cmd.exe with a high level of access or any other kinds of instructions.<\/p>\n<h2>Technical Explanation<\/h2>\n<p>A sample of miner malware that used this vulnerability for its distribution, instructs its desired Weblogic Server to execute XML codes which leads to downloading a Powershell file and eventually results in a system infection. In the following image you can see how the malware uses this vulnerability:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-461\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2021\/03\/Untitled245.png\" alt=\"\" width=\"1027\" height=\"277\" \/><\/p>\n<h3>Security recommendation<\/h3>\n<p>For being safe, restrict the access of the Weblogic Server admin portal to the local network and also make sure that it is updated with the last version of the provided patch.<\/p>\n<h2>How to deal with it<\/h2>\n<p>Padvish antivirus IPS (Intrusion Prevention System) detects all attempts to infect the system by these types of vulnerabilities and prevents them from entering the system.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>General explanation Type: Vulnerability Vulnerability platform: Oracle WebLogic Server Vulnerability versions: 10.3.6.0.0- 14.1.1.0.0 The date of representing of the patch by Microsoft: October 2020 Vulnerability module: Console Component Vulnerability type: Unauthenticated Remote Code Execution Degree of destruction: high Used Malware: Miner.Win64.CoinMiner.a Trojan.Win32.DarkIRC.Ss1 What is Vulnerability? In computer security, Vulnerability is a defect inside a platform&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[16],"class_list":["post-460","post","type-post","status-publish","format-standard","hentry","category-exploit","tag-ips"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=460"}],"version-history":[{"count":6,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/460\/revisions"}],"predecessor-version":[{"id":1285,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/460\/revisions\/1285"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=460"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=460"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}