cbcvebase.
CVE-2020-7961
published 2020-03-20

CVE-2020-7961: Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.77%
100.0th percentile
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

Affected

1 ranges
VendorProductVersion rangeFixed in
liferayliferay_portal< 7.2.17.2.1

Detection & IOCsextracted from sources · hover to see the quote

domaingxbrowser[.]net
urlhttp://gxbrowser[.]net/out.py
domaincnc[.]tacobelllover[.]tk
domainbp65pce2vsk7wpvy2fyehel25ovw4v7nve3lknwzta7gtiuy6jm7l4yd[.]onion[.]ws
ip212.84.32[.]13
ip103.25.196[.]33
urlhttp://209.14.0[.]234:56138/iMCRufG79yXvYjH0W1SK
filenameCacheTask.dll
filenameHostDLL.exe
  • FreakOut bots identify themselves on IRC with the nickname format [HAX| <OS> | <arch> | <cpu_count> ] <8-12 random chars>; detect this pattern in outbound IRC traffic.
  • Compromised Liferay servers used as post-exploitation payload hosts on non-standard ports (not 80, 443, 8080); monitor outbound connections from internal hosts to Liferay CMS IPs on high/unusual ports.
  • CVE-2020-7961 is part of the FreakOut 'unholy trinity' alongside CVE-2020-28188 and CVE-2021-3007; network sensors should correlate exploit attempts across all three CVEs from the same source IP as a high-confidence FreakOut indicator.
  • ·The FreakOut malware (out.py) is polymorphic and re-obfuscated on every download with random function/variable names, making static hash-based detection unreliable; behavioral detection is preferred.
  • ·The C2 IRC credentials (channel key, server address) are obfuscated and encoded multiple times within the bot code; extraction requires dynamic analysis or unpacking of the packing function.
  • ·Liferay servers observed as payload hosts were running the vulnerable CE version 6.2 (CVE-2020-7961 affects versions prior to 7.2.1 CE GA2); the servers appeared to be compromised third-party infrastructure, not attacker-owned.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.