Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability in Newforma Info Exchange allows remote attackers to execute code on affected systems with elevated privileges. This issue impacts Newforma Project Center Server, which relies on the vulnerable Info Exchange component for its operations, potentially exposing associated project data.
- Remote code execution in Newforma systems.
- Critical flaw impacts external collaboration platform.
- Assess relevance and exposure for project data.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can reach a vulnerable endpoint on Newforma Info Exchange (NIX) to send specially crafted data. This data can be processed by the Newforma Project Center Server (NPCS), potentially allowing the attacker to execute arbitrary code with network service privileges on the NPCS system.
- Attacker can reach an internet-facing service.
- Sending malicious serialized .NET data triggers vulnerability.
- Attacker can gain privileged code execution.
Live Threat
Current exploitation, exposure, and threat context
A remote, unauthenticated attacker could execute arbitrary code on systems running Newforma Info Exchange when interacting with the '/remoteweb/remote.rem' endpoint. This could allow an attacker to compromise an associated Newforma Project Center Server.
- System code execution is at risk.
- Attackers send malicious .NET data.
- Compromised servers could result.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Newforma Project Center Server (NPCS) team, likely in coordination with platform or infrastructure teams, is responsible for securing the Newforma Info Exchange (NIX) environment. The first step is to identify all NIX instances, determine their network reachability, confirm their criticality, and locate the accountable owner for remediation planning.
- Identify affected systems and owners.
- Verify external reachability of the endpoint.
- Plan and coordinate remediation efforts.