Zero-Day Exploits in SonicWall Email Security Lead to Enterprise Compromise

Read the original article: Zero-Day Exploits in SonicWall Email Security Lead to Enterprise Compromise

In March 2021, Mandiant Managed Defense identified three zero-day
vulnerabilities in SonicWall’s Email Security (ES) product that were
being exploited in the wild. These vulnerabilities were executed in
conjunction to obtain administrative access and code execution on a
SonicWall ES device. The adversary leveraged these vulnerabilities,
with intimate knowledge of the SonicWall application, to install a
backdoor, access files and emails, and move laterally into the victim

Content was cut in order to protect the source.Please visit the source for the rest of the article.

Read the original article: Zero-Day Exploits in SonicWall Email Security Lead to Enterprise Compromise