Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability exists in the Salesforce Workbench tool that could allow an attacker to execute code remotely if a user interacts with a specially crafted cookie. This issue is present in versions prior to 65.0.0 and has been addressed in the latest release.
- Remote code execution flaw in admin tool.
- Affects how administrators manage Salesforce.
- Confirm relevance and exposure to Salesforce tools.
Attack Path
How an attacker could exploit the issue
An attacker could reach and trigger this vulnerability by presenting a specially crafted cookie to a user interacting with Workbench. This interaction could lead to remote code execution if the vulnerable timezone conversion flow processes the malicious cookie value.
- Unauthenticated user interaction required.
- Unsafe processing of attacker-controlled cookie.
- Potential for remote code execution.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, a remote code execution vulnerability in the timezone conversion flow could affect system data and service behavior due to unsafe processing of attacker-controlled cookie values.
- System data and configuration could be affected.
- Attackers could exploit unsafe cookie processing.
- Malicious code execution may occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners and infrastructure teams are likely responsible for addressing this vulnerability in Workbench, a suite of tools for interacting with Salesforce.com organizations. The first practical step is to identify all instances of Workbench, confirm their accessibility and business criticality, and then assign ownership for remediation planning.
- Identify Workbench instances and ownership.
- Verify exposure and business criticality.
- Plan risk-based remediation actions.