TL;DR

GFI Archiver's MARC.Core module is vulnerable to deserialization, enabling attackers to execute remote code post-authentication bypass.

What happened

['Remote code execution in GFI Archiver via MARC.Core component', 'Bypassing authentication for exploitation']

Why it matters for ops

['Critical CVSS rating of 8.8 highlights severe risk', 'Authentication mechanisms can be circumvented']

Mitigation

  • Apply vendor-provided patches immediately
  • Monitor and restrict access to MARC.Core component

Action items

  • Update GFI Archiver to the latest version
  • Configure strict authentication policies

Detection IOCs

  • Unusual deserialization requests to MARC.Core component
  • Remote code execution attempts post-authentication bypass

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-074/