← Incident database

moveit-2023 · Disclosed 2023-05-31

MOVEit: SQL injection exploited before disclosure

A MOVEit Transfer SQL injection vulnerability was exploited before disclosure. Investigators observed web shells and data theft, requiring investigation alongside updates.

Zero-dayImplementationCVE-2023-34362

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    The earliest exploitation evidence in Mandiant response engagements was May 27, 2023.

    [s1]Overview
  • Reported fact

    The product SQL injection vulnerability was identified as CVE-2023-34362.

    [s2]CVE-2023-34362

Timeline

  1. Earliest observed exploitation in the cited investigation. [s1]

  2. Vendor disclosed the vulnerability. [s3]

Reported response

  • Reported fact

    The vendor supplied mitigation and patch guidance to customers.

    [s3]Customer response

Evidence relevant to prevention

Exploited before disclosure

A later patch cannot prevent an earlier compromise. Inspect exposure controls and incident investigation and recovery paths.

Editorial assessment; not a determination of liability. [s1][s2][s3]

Unknowns and AI involvement

AI involvementUnknown

The cited primary sources do not establish AI involvement. This does not establish that AI was absent.

Victim timelines vary. Distinguish a vendor defect from SQL injection in your own code.

Sources

  1. [s1] Mandiant · Primary source

    Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft ↗

    Published 2023-06-02 · Reviewed 2026-10-02

  2. [s2] NIST NVD · Primary source

    CVE-2023-34362 Detail ↗

    Published 2023-06-02 · Reviewed 2026-10-02

  3. [s3] Progress · Primary source

    An Update on the Steps We are Taking to Protect MOVEit Customers ↗

    Reviewed 2026-10-02