TL;DR

A critical RCE flaw in GFI Archiver allows bypassing authentication for remote execution of commands, rated CVSS 8.8 by ZDI.

What happened

['Remote code execution vulnerability in MARC.Store component', 'Authentication mechanism can be bypassed']

Why it matters for ops

['Exploits allow unauthorized access and command execution', 'Potentially leads to data theft or system compromise']

Mitigation

  • Apply vendor-provided patches immediately
  • Monitor affected systems for signs of exploitation

Action items

  • Update to the latest version with security fixes
  • Review and adjust authentication protocols

Detection IOCs

  • Unusual outbound network traffic from GFI Archiver server
  • Unexpected file modifications in MARC.Store directories

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-076/