HC3 warns of critical vulnerabilities in MOVEit platform that pose enhanced risk to healthcare sector - #CVE-2024-5805
The cybersecurity community has been alerted to critical vulnerabilities in Progress Software's MOVEit file transfer platform, specifically in the MOVEit Transfer and MOVEit Gateway components. These authentication bypass flaws, identified as CVE-2024-5806 and CVE-2024-5805, allow unauthorized access to sensitive data, enabling threat actors to upload, download, modify, or delete files on affected servers. While patches have been released, exploitation attempts have been observed, and proof-of-concept code is publicly available, underscoring the urgency for organizations to update their systems. Healthcare organizations, which extensively utilize MOVEit for secure file transfers, are particularly vulnerable and urged to prioritize patching to mitigate potential ransomware attacks and data breaches.