A critical zero-day vulnerability in Magento and Adobe Commerce is being weaponized to install a persistent Linux backdoor, escalating attacks from data theft to full server compromise. Security researchers report that the flaw grants attackers enduring access that persists across system reboots and even after initial patching.
Tracked as CVE-2024-2977 with a CVSS score of 9.8, the vulnerability resides in the Layout processing module of the platforms. Threat actors linked to the SanSec group are exploiting this flaw as the entry point for an attack chain that deploys a backdoor dubbed "DotVanilla."
This campaign diverges from typical e-commerce attacks, which aim to skim payment card data. Instead, it focuses on establishing long-term control over compromised servers. The "DotVanilla" backdoor provides a hidden persistent foothold, meaning that merely patching the Magento application is inadequate for breached systems. Organizations must conduct forensic investigations to determine if a compromise occurred pre-patch and may need to rebuild affected servers entirely.
The attack primarily targets self-hosted Magento installations running on Linux servers, putting organizations managing their own e-commerce infrastructure at highest risk. Those relying on fully managed cloud or hosting services may face different exposure levels.
In response, Adobe has released emergency patches for CVE-2024-2977 and urges immediate application by all users of affected versions. Public detailing of the vulnerability heightens the risk of widespread exploitation attempts.
For administrators of self-hosted Magento stores, this incident underscores the necessity of defense-in-depth. Applying the vendor patch is the essential first step, but it must be followed by comprehensive log reviews, integrity checks of server files, and audits of user accounts and permissions to rule out prior compromise. The shift from a web application exploit to an OS-level backdoor illustrates the deep system access achievable without rigorous security measures.
Magento及Adobe Commerce平台存在一個關鍵零日漏洞正遭惡意利用,用於安裝持續性Linux後門程式,令攻擊手段從竊取數據升級至完全控制伺服器。安全研究報告指出,該漏洞賦予攻擊者持久存取權限,即使系統重啟或完成初步修補後仍可持續生效。
此漏洞編號為CVE-2024-2977(CVSS評分9.8),存在於平台的版面處理模組。與SanSec組織相關的威脅行為者正利用此漏洞作為攻擊鏈入口,部署代號「DotVanilla」的後門程式。
這次攻擊行動有別於常見的電子商務攻擊——後者通常以竊取支付卡資料為目標,而是專注於建立對受入侵伺服器的長期控制權。「DotVanilla」後門程式提供隱蔽的持續性據點,意味著僅修補Magento應用程式不足以應對已遭入侵的系統。相關機構必須進行數位鑑識調查,以確定漏洞是否在修補前已被利用,可能需要完全重建受影響的伺服器。
攻擊主要針對運行於Linux伺服器的自建Magento安裝環境,使自主管理電子商務基礎設施的機構面臨最高風險。採用全託管雲端或主機服務的機構,其受影響程度可能有所不同。
Adobe已針對CVE-2024-2977發布緊急修補程式,敦促所有受影響版本用戶立即套用。由於漏洞細節已公開,大規模利用攻擊的風險隨之增加。
對於自建Magento商店的管理員而言,此事件突顯了縱深防禦策略的必要性。套用廠商修補程式是首要基本步驟,但後續必須進行全面日誌審查、伺服器檔案完整性檢查,以及用戶帳號與權限審計,以排除先前已被入侵的可能性。此次攻擊從網頁應用程式漏洞利用轉向作業系統層級後門程式,清楚說明了缺乏嚴謹安全措施時可能造成的深層系統入侵。
