<p>Attackers are actively scanning for vulnerable Elasticsearch systems in order to implant cryptocurrency mining scripts.</p>
<h3>Background</h3>
<p>In recent weeks, attackers have been <a href="https://isc.sans.edu/diary/rss/24364">observed scanning for vulnerabilities in Elasticsearch</a>, a distributed, RESTful search and analytics engine. According to <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/cryptocurren... from Trend Micro</a>, the attackers are targeting unpatched Elasticsearch systems using vulnerabilities from 2014 and 2015 to break into systems in order to implant cryptocurrency mining (also known as “coinminer”) scripts. These scripts are designed to hijack a system’s computing resources in a race to solve complex mathematical problems (“mining”) first in order to receive a reward of cryptocurrency.</p>
<h3>Vulnerability details</h3>
<p>The Elasticsearch vulnerabilities used in these attacks include <a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3120">CVE-2014-3120</a>, a remote code execution vulnerability in the ‘source' parameter of the '/_search' page as part of the Elasticsearch default configuration and <a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1427">CVE-2015-1427</a>, a remote code execution vulnerability in the Groovy scripting engine part of the default configuration in Elasticsearch up to version 5.0.0. Successful exploitation of these vulnerabilities can allow an attacker to execute arbitrary code, gain a remote shell or manipulate files on the remote system. </p>
<h3>Urgently required actions</h3>
<p>Upgrading to Elasticsearch version 1.2.0 or later resolves CVE-2014-3120 while upgrading to version 1.3.8 / 1.4.3 or later resolves CVE-2015-1427. Disabling scripting altogether will also mitigate these vulnerabilities. It is also extremely important to ensure your <a href="https://www.elastic.co/guide/en/elastic-stack-overview/current/elasticse... is properly secured</a>.</p>
<h3>Identifying affected systems</h3>
<p>A list of Nessus plugins to identify these vulnerabilities can be found <a href="https://www.tenable.com/plugins/search?q=cves%3A(%22CVE-2015-1427%22%20OR%20%20%22CVE-2014-3120%22)&sort=newest&page=1">here</a>.</p>
<h3>Get more information</h3>
<ul>
<li><a href="https://isc.sans.edu/diary/rss/24364">CoinMiners searching for hosts</a></li>
<li><a href="https://blog.trendmicro.com/trendlabs-security-intelligence/cryptocurren... Miner Spreads via Old Vulnerabilities on Elasticsearch</a></li>
<li><a href="https://www.elastic.co/guide/en/elastic-stack-overview/current/elasticse... the Elastic Stack</a></li>
</ul>
<p><b><i>Learn more about <a href="https://www.tenable.com/products">Tenable</a>, the first Cyber Exposure platform for holistic management of your modern attack surface. Get a <a href="https://www.tenable.com/products/tenable-io/vulnerability-management/eva... 60-day trial</a> of Tenable.io Vulnerability Management. </i></b></p>