Executive brief
TeamT5 ThreatSonar Anti-Ransomware is a security solution designed to protect corporate endpoints from ransomware attacks. A vulnerability in the platform allows an attacker with administrative access to upload malicious files to the server. If exploited, this could allow the attacker to take full control of the security server, potentially disabling ransomware protections or accessing sensitive internal data.
Technical details
The vulnerability (CWE-434) exists in TeamT5 ThreatSonar Anti-Ransomware due to improper validation of uploaded file content. A remote attacker with high privileges (administrator) can bypass file type restrictions to upload malicious scripts or executables to the product platform. Once uploaded, these files can be executed to achieve arbitrary command execution on the underlying server. This vulnerability has been observed in the wild and is included in the CISA Known Exploited Vulnerabilities (KEV) catalog. The issue is addressed in version 3.5.0.
Affected products
- TeamT5 ThreatSonar Anti-Ransomware versions up to (excluding) 3.5.0
Timeline
- 2024-08-12: disclosed: Initial NVD publication
- 2024-09-06: patched: NIST analysis identifies fix in version 3.5.0
- 2026-02-17: kev added: Added to CISA Known Exploited Vulnerabilities catalog