Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the pwn.college DOJO cybersecurity education platform could allow unauthorized access to active Windows virtual machines. This issue stems from improper authentication on the `/workspace` endpoint, where user access is not adequately verified.
- Unauthorized users can access Windows VMs.
- Critical for educational platforms handling sensitive data.
- Confirm relevance and assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by accessing the /workspace endpoint without needing any special privileges or authentication. By manipulating URL parameters, an attacker can impersonate any user, bypass password checks, and gain unauthorized access to active Windows virtual machines. This allows them to view and modify data on the Windows machine and access files on the associated Linux home directory.
- No authentication required for access.
- Triggered by manipulating URL parameters.
- Unauthorized access to Windows VMs.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthorized user to access and modify data on any active Windows virtual machine within the pwn.college DOJO platform. The exposure occurs when the `/workspace` endpoint is accessed, as it improperly verifies user credentials, enabling an attacker to impersonate any user and gain full access to their Windows VM and associated Linux home directory.
- Access to active Windows VMs.
- Impersonation via the `/workspace` endpoint.
- Modification of VM and home directory data.
Operational Fix
Recommended remediation, mitigation, and detection steps
The pwn.college DOJO platform's education application owners and infrastructure teams are primarily responsible for addressing this critical authentication bypass vulnerability. The immediate first step is to identify all instances of the DOJO platform, confirm which are internet-facing and actively used for Windows VM access, and then assign ownership for remediation planning.
- Application owners should manage remediation efforts.
- Verify all internet-facing Windows VM instances.
- Plan risk-based remediation with vendor coordination.