Jump to content

3CX security issue


Recommended Posts

 

https://www.3cx.com/blog/news/desktopapp-security-alert/

 

What about this issue? Does malwarebytes detect it? We had the malicous version installed but didn't get a threat warning.

Edited by AdvancedSetup
Disabled live hyperlinks
Link to post
Share on other sites

Hello.
First, it would be most helpful to know if you are in a business / organization / enterprise type network running the Business Malwaeebytes ( Nebula or other app) ??
or, whether this is a home type system ?
It helps to know the version of Malwarebytes being used.

Malwarebytes detects the malicious DDLs as Trojan.Agent.

See my reply below https://forums.malwarebytes.com/topic/296399-3cx-security-issue/?do=findComment&comment=1561167

 

Edited by Maurice Naggar
amended
Link to post
Share on other sites

3CX Desktop App is a voice-over-IP business application. NOTE what the vendor has stated on the page you cited

Currently, we’re working on a new Windows App that does not have the issue. We've also decided to issue a new certificate for this app. This will delay things by at least 24 hours so please bear with us.

Link to post
Share on other sites

Link to post
Share on other sites

@nitramz

The Malwarebytes BLOG has a very handy set of remediation advice. Please be sure to give it strong consideration.
3CX desktop app used in a supply chain attack
https://www.malwarebytes.com/blog/news/2023/03/3cx-desktop-app-used-in-a-supply-chain-attack

Here is a snippet from that page

What needs to be done?

After initially playing down the alerts on its user forums as a possible false positive, 3CX has now posted that it is working on an update.

The advice on the 3CX forums is to uninstall the app and then reinstall it, accompanied by a strong advice to install the PWA client instead.

Malwarebytes detects the malicious DDLs as Trojan.Agent.

Malwarebytes blocks Trojan.Agent

We will keep you updated here, but as a user you might want to keep an eye on 3CX’s blog and forums to learn about new developments, and when an update is available.

Link to post
Share on other sites

  • Root Admin

Fixing what looks to be like a 10 year old bug might also help protect the computer.

https://www.bleepingcomputer.com/news/microsoft/10-year-old-windows-bug-with-opt-in-fix-exploited-in-3cx-attack/

 

Windows Registry Editor Version 5.00  

[HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config]   
"EnableCertPaddingCheck"="1"

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config] 
"EnableCertPaddingCheck"="1"

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.