Horizon Alert
Summary of the vulnerability and why it matters
This advisory highlights a critical vulnerability in Newforma Project Center Server that could allow an unauthenticated attacker to execute arbitrary code. While the affected endpoint is intended for internal network use, its presence warrants confirmation of its accessibility.
- Code execution flaw in Project Center Server.
- Internal network systems may be at risk.
- Confirm relevance and exposure internally.
Attack Path
How an attacker could exploit the issue
An attacker could target the Newforma Project Center Server by sending serialized .NET data to its '/ProjectCenter.rem' endpoint. This endpoint is exposed on TCP port 9003, and according to the product's typical architecture, it is accessible from within an internal network. If successful, this could allow the attacker to execute arbitrary code on the server with the privileges of 'NT AUTHORITY\\NetworkService'.
- Requires internal network access.
- Vulnerable endpoint accepts serialized data.
- Leads to arbitrary code execution.
Live Threat
Current exploitation, exposure, and threat context
When Newforma Project Center Server is accessible on an internal network, an unauthenticated attacker could potentially execute arbitrary code. This could impact the confidentiality, integrity, and availability of the affected system.
- System data and service behavior are at risk.
- Exposure can occur via the Project Center Server endpoint.
- Arbitrary code execution could occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Newforma Project Center Server, when exposed via the `/ProjectCenter.rem` endpoint, presents a critical risk of arbitrary code execution. Given that the recommended architecture places this endpoint on an internal network, the primary responsibility likely falls to the Infrastructure and Security Teams to ensure network segmentation and access controls are strictly enforced. The initial practical step involves identifying all instances of the Project Center Server, confirming their network reachability, and assessing their business criticality to prioritize remediation efforts.
- Own the issue: Infrastructure and Security Teams.
- Verify first: Network accessibility and business criticality.
- Action: Restrict network access to the endpoint.