
Armadin obtained remote code execution (RCE) on an enterprise cloud backup solution through a chain of vulnerabilities requiring only network access to the application.
Externally accessible cloud backup solutions are enticing targets for attackers. They often run with high privileges, have access to sensitive data and environments, and expose a wealth of functionality that could be abused through an authentication bypass.
Armadin’s work started with reverse engineering of the application, initially focused on expanding the attack surface past an unauthenticated user. After identifying an authentication bypass, Armadin focused on functionality that could provide internal network access to a privileged user.
The full RCE chain followed:
Armadin focuses heavily on authentication bypasses when attacking externally accessible applications. An application’s unauthenticated footprint is usually small, while the expanded functionality of a privileged user often leads to high-impact vulnerabilities. In this case, the authentication bypass vulnerability expanded access into local file management functionality.
Kill chains that include an initial vulnerability that expands the accessible functionality have become a common pattern for external web application compromise. Vulnerabilities that increase application access, like authentication bypasses and server-side request forgery (SSRF), can turn a relatively small external attack surface into a much larger one.
The application, like most cloud backup products, contained extensive local file management functionality by design. One such feature allowed a privileged user to create new directories to store file uploads for incoming backups but did not validate that the selected directory was the application’s web root.
Armadin leveraged this issue, along with the ability to upload arbitrary files, to upload a web shell into the web root, granting command execution as NT AUTHORITY\SYSTEM on the cloud backup server.
This combination has become increasingly common in the kill chains Armadin has found. Externally accessible applications expose sensitive functionality by design to privileged users. A vulnerability that provides access to those privileges can quickly turn intended administrative functionality into a path to application compromise.
Even in the age of machine-speed AI attacks, good security hygiene limits the impact of a compromised application.
Armadin recommends limiting the exposure of management interfaces to the public Internet through a combination of virtual private networks (VPNs), IP address allowlisting, and zero-trust network access (ZTNA) solutions.
In instances where applications must be externally exposed, they should have limited access to sensitive internal network systems. Exposed applications should live within a DMZ, cordoned off from other networks to limit the impact of compromise.
Special thanks to Nick Cerne for his discovery of these vulnerabilities.
Discover how a safe Hyperattack assessment from Armadin gives you the tools and confidence to identify exploitable risk across your environment. Learn more about Hyperattacks.