CVE-2023-0669
HIGH KEV RANSOMWARE NUCLEIFortra GoAnywhere MFT Unsafe Deserialization RCE
Title source: metasploitExploitation Summary
CVE-2023-0669 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 10, 2023, with confirmed use in ransomware campaigns.
EIP tracks 7 public exploits from researchers including Youssef Muhammad, 0xf4n9x, Avento, including a Metasploit module exploits/multi/http/fortra_goanywhere_rce_cve_2023_0669.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Java-based helper tool encrypts a serialized payload generated by ysoserial to exploit CVE-2023-0669, a deserialization vulnerability in GoAnywhere Encryption Helper. It supports two encryption versions and outputs a Base64-encoded payload for RCE.
Description
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.
Exploits (7)
This Java-based helper tool encrypts a serialized payload generated by ysoserial to exploit CVE-2023-0669, a deserialization vulnerability in GoAnywhere Encryption Helper. It supports two encryption versions and outputs a Base64-encoded payload for RCE.
This repository contains a functional exploit for CVE-2023-0669, a pre-authentication command injection vulnerability in GoAnywhere MFT. The exploit leverages deserialization of an attacker-controlled object via the License Response Servlet to achieve remote code execution.
This is a Python-based exploit for CVE-2023-0669, a pre-authentication deserialization vulnerability in GoAnywhere MFT. It crafts a malicious serialized object, encrypts it, and sends it to the target to achieve remote code execution.
This repository provides analysis and references for CVE-2023-0669, an unauthenticated RCE vulnerability in GoAnywhere. It includes a link to a vulnerable version of the software but does not contain exploit code.
This repository provides a Docker-based simulation of CVE-2023-0669, a deserialization vulnerability in Fortra GoAnywhere MFT. It includes an attacker container generating a malicious payload using ysoserial, a vulnerable server container, and a listener container to confirm exploitation via a curl-based callback.
This repository contains only a README file describing CVE-2023-0669, a command injection vulnerability in GoAnywhere MFT. No exploit code or technical details are provided.
This Metasploit module exploits CVE-2023-0669, an unsafe deserialization vulnerability in Fortra GoAnywhere MFT. It generates a malicious serialized Java object, encrypts it, and sends it to the target endpoint to achieve remote code execution.
Nuclei Templates (1)
http.favicon.hash:1484947000 || http.favicon.hash:1484947000,1828756398,1170495932
app="goanywhere-mft" || icon_hash=1484947000 || icon_hash=1484947000,1828756398,1170495932
References (9)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H