Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Overview
Researchers have discovered multiple remote code execution (RCE) vulnerabilities in several versions of Redis, a widely used in-memory data structure store. The vulnerabilities affect Redis versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0, with specific exploitation chains requiring commands like RESTORE, EVAL, and XGROUP. Redis confirmed that these memory flaws could allow attackers to execute arbitrary code remotely. In response, Redis released seven security updates on July 23 to address these issues, including versions 6.2.23, 7.2.15, and 7.4.10. Users of these affected versions need to update their systems promptly to protect against potential exploitation.
Key Takeaways
- Affected Systems: Redis versions 6.2.22, 7.4.9, 8.6.4, 8.8.0
- Action Required: Upgrade to Redis versions 6.
- Timeline: Disclosed on July 23, 2023
Original Article Summary
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution. Redis 6.2.23, 7.2.15, and 7.4.10
Impact
Redis versions 6.2.22, 7.4.9, 8.6.4, 8.8.0
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Disclosed on July 23, 2023
Remediation
Upgrade to Redis versions 6.2.23, 7.2.15, or 7.4.10
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Exploit, Vulnerability, Update, and 2 more.