Proxmox VE 7 is vulnerable to some type of 0day/RCE non auth

In any case, I don't think this is a 0day vulnerability, because on this is happen due to out date servers and bad servers administration, to say the least.
Everything happened on the same day at the same time. Of course, it's a zero-day vulnerability and affects several versions of Proxmox. Exposing Proxmox to the internet doesn't make it hackable with a single click. There are no publicly available non-auth exploits for versions 7 or 8. The non-auth SSHD bug in Debian 12 would affect the earliest versions of Proxmox VE 8, not versions 7 or 8.4.
 
Last edited:
Everything happened on the same day at the same time. Of course, it's a zero-day vulnerability and affects several versions of Proxmox.
Only to you, unless you are claiming that it affects an up-to-date version of PVE.

Exposing Proxmox to the internet doesn't make it hackable with a single click. There are no publicly available non-auth exploits for versions 7 or 8. The non-auth SSHD bug in Debian 12 would affect the earliest versions of Proxmox VE 8, not versions 7 or 8.4.
PVE 7 is based on Debian 11, PVE 8 on Debian 12. So they would be affected by that bug unless they were updated since the bug was fixed.
 
Everything happened on the same day at the same time.
Not sure what you mean by "Everything". So far you only reported your own single host being attacked.
Are you (by chance) connected to arjitc, the other reporter of this attack. (Interestingly both these users only joined today, for the purpose of these reports!)


it's a zero-day vulnerability and affects several versions of Proxmox.
How on earth do you know any of that?



I'm not a troll
So if accused of being a troll, we now know you can't be!

You could not remember if your host was open to the net.... Interesting.

Anyway, whatever the case, this serves as a warning to all users, do not run any OS EOL/un-updated & do not expose a host to the net that is not hardened effectively.
 
Last edited:
Some people in this community are being toxic. This attack was clearly caused by a security vulnerability in PVE, a 0day, yet many are still blaming users for not running the latest version, PVE 9.

However, several points need to be considered:

1. PVE 8 was still officially supported on the day the attack occurred.

2. Many users are enterprise environments, not casual home lab hobbyists. You cannot simply expect them to drop everything, accept the downtime, and perform a major cross-version system upgrade on the fly. You cannot approach a large-scale system with the mindset of a casual home lab hobbyist.

3. We already have the exp for one of the vulnerabilities affecting PVE 7 through PVE 8.0.4. While I am not certain whether 8.2 and 8.4 are affected, there are plenty of reported cases in the community.

4. The attacker clearly knew that these past couple of days marked the EOL for PVE 8, so they deliberately chose this window to start exploiting this high-value 0day.
 
Last edited:
The usual use of the zero-day term is for vulnerabilities that are being exploited while there is no fix yet (for a supported/current version). That is something the administrator cannot do much about. This vulnerability is probably already fixed in a later (supported) Proxmox/Debian/Linux version, which makes it a known vulnerability with a known attack that only works against outdated (unsupported) Proxmox/Debian/Linux. This is something the administrator can prevent; this is not news or urgent, this is to be expected.
Nevertheless, people running into this might be able to share information to help each other on this forum. And it's a good showcase for staying up to date for others.
 
Last edited:
Are you (by chance) connected to arjitc, the other reporter of this attack. (Interestingly both these users only joined today, for the purpose of these reports!)
I'm unrelated to the other user, the only reason I signed up was after seeing the post on the other forum :)

PVE 7 is based on Debian 11, PVE 8 on Debian 12. So they would be affected by that bug unless they were updated since the bug was fixed.

If I remember correctly at the time Debian 11 wasn't affected by that SSH bug

EDIT: I found this and it seems like Debian 11 wasn't affected by CVE-2024-6387 (https://security-tracker.debian.org/tracker/CVE-2024-6387)
 
Last edited:
Systems without current system updates can be hacked, nothing is "new" or "urgent" on this. And PVE7 and PVE8 won't get any security updates any more so it's somehow expected that they get owned. Even if you don't connect them directly to the Internet a bad actor could still first get some access to another (directly connected) machine in your network and use it as a jump host to your PVE host. Nothing on this an ProxmoxVE issue but with systems, which are not updates. It doesn't matter if the culprit is a lazy system administrator or some some damager with title "change manager" or "compilance manager" who thinks "never change a running system" is still a good idea in the age of KI assisted "security research" and hacking. It wasn't a good idea before to install updates only one time a year or less. In this age it's gross neglect and incompetence to have a EOL system in production instead of a museum. Nothing on this is an ProxmoxVE or Debian or Linux issue at all.
And I also don't get the point of socket puppet accounts which says "I'm affected too". Yes, you are affected from your miss-management, change the broken processes in your company, but it's off topic here.
 
Last edited:
Systems without current system updates can be hacked, nothing is "new" or "arguent" on this. And PVE7 and PVE8 won't get any security updates any more so it's somehow expected that they get owned. Even if you don't connect them directly to the Internet a bad actor could still first get some access to another (directly connected) machine in your network and use it as a jump host to your PVE host. Nothing on this an ProxmoxVE issue but with systems, which are not updates. It doesn't matter if the culprit is a lazy systemupdate or some some damager with title "change manager" or "compilance manager" who thinks "never change a running system" is still a good idea in the age of KI assisted "security research" and hacking. It wasn't a good idea before to install updates only one time a year or less. In this age it's gross neglect and incompetence to have a EOL system in production instead of a museum. Nothing on this is an ProxmoxVE or Debian or Linux issue at all.
And I also don't get the point of socket puppet accounts which says "I'm affected too". Yes, you are affected from your miss-management, change the broken processes in your company, but it's off topic here.
You're absolutely right...
 
Having read that post (& translating the Chinese!) & all comments, I believe it is a scam. Read it carefully.

You're completely dodging the point right now.
I don't think so. I've already stated above:
Anyway, whatever the case, this serves as a warning to all users, do not run any OS EOL/un-updated & do not expose a host to the net that is not hardened effectively.
 
Some people in this community are being toxic.

I disagree. I think it's more toxic to have EOL systems (like PVE7) on the Internet. It makes the world for all a worse place. I also think it's toxic to register accounts to cry about about an "Proxmox security issue" which quite obviouvsly isn't an ProxmoxVE issue but one with the (lack of) competence of sysadmins and change managment.

1. PVE 8 was still officially supported on the day the attack occurred.
This might be, Debian Bookworm (the base for PVE8) however isn't:
https://wiki.debian.org/LTS

It's now under LTS which means that it's not done by the Debian security team anymore and not all packages are covered.

This attack was clearly caused by a security vulnerability in PVE, a 0day, yet many are still blaming users for not running the latest version, PVE 9.

Rightfully since it's definitevley not best practice to camp on old, unsupported versions. That a lot of enterprises do this nontheless doesn't make this "worst practice" a "good practice". And while I'm willing to give some leeway in case of some propietary software which is business-critical and only runs on an old systems (I had the joy of dealing with such a piece of crap myself at my place of work) this is NOT the case for a KVM-based hypervisor. PVE9 was published more than a year ago, PVE8 was released in 2023. Even if you don't want to update to the 8.0 or 9.0 release, people had more than enough time to update from PVE7 to PVE8 and then again to PVE9.

But that wasn't the only bug found in SSH over the last five years.
The Kernel alone had quite a lot of security issues that's just the state of the world we live in.

4. The attacker clearly knew that these past couple of days marked the EOL for PVE 8, so they deliberately chose this window to start exploiting this high-value 0day.

I doubt that typical attachers (ransomware gangs) actually care about things as time windows. Their strategy is basically to just scan any potential system for any potential known security issue since more than enough "enterprise" environments don't update ever. You don't need to invest much time in timing an attack or only use exploits for EOL systems if many "enterprises" are stupid enough not to install security patches even if they are available. Basically for their business model it's enough if from thousand attacked systems just one gets owned and the victim is willing to pay ransom. You don't need to waste any effort in timing attacks, if sysadmins and managment are just lazy.
 
Last edited:
Having read that post (& translating the Chinese!) & all comments, I believe it is a scam. Read it carefully.


I don't think so. I've already stated above:

Having read that post (& translating the Chinese!) & all comments, I believe it is a scam. Read it carefully.


I don't think so. I've already stated above:
I have a compromised Proxmox 7 system, and they left me with those files shown in the screenshots and the same message that appears on the Chinese website... it's clearly a scam... although they encrypted the LVM unit located at /var/lib/vz
 
I have a compromised Proxmox 7 system, and they left me with those files shown in the screenshots and the same message that appears on the Chinese website... it's clearly a scam... although they encrypted the LVM unit located at /var/lib/vz
That's entirely your fault.

You are running a version of Proxmox that has been EOL for 2 years.
 
I still think a more productive way to look at this would be to see if there's any possible/remaining logs, to see what could've exactly caused this, and then list exact affected versions?

So far reading between the posts here and the other forum, it seems like something between v7.0.x and v8.0.2-8.0.4 being affected? or has anyone seen anything newer like v8.4 also being affected?
 
I still think a more productive way to look at this would be to see if there's any possible/remaining logs, to see what could've exactly caused this, and then list exact affected versions?

So far reading between the posts here and the other forum, it seems like something between v7.0.x and v8.0.2-8.0.4 being affected? or has anyone seen anything newer like v8.4 also being affected?
Got reports till 8.4.0
 
Got reports till 8.4.0
You're just too late for Proxmox to spend time and money on this. PVE 8.4.21 is just about EoL and out of support (and it did get several updates beyond 8.4.0). PVE 9 did get a lot of CVE fixes via the Linux kernel and Debian recently that might have fixed it already. Please let us know which CVE was used to get into PVE 8.4.0.
 
Last edited: