Skip to content
← LibraryTechnique entry
CVE-MOVEITInitial Access

MOVEit Transfer SQLi → Deserialisation (CVE-2023-34362)

Pre-auth SQLi in MOVEit's web UI → forge admin session → .NET deserialisation chain → SYSTEM webshell. The Cl0p mass-exfil event of 2023.

§ Where this technique fits

CVE-MOVEIT is catalogued under the Initial Access tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 2 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01seen 1×