Critical Zero-Day Vulnerability in Ozols Grupa Exposes DIB and Enterprise Systems to Remote Code Execution
Overview
A critical vulnerability in Ozols Grupa's software components, rated CVSS 10.0, allows attackers to execute arbitrary code on affected systems through a compromised update channel. This exposes Defense Industrial Base (DIB) and enterprise environments to severe risks, including complete system compromise.
Technical Analysis
The vulnerability stems from the absence of integrity checks in OzolsSQL's auto-update process, enabling adversaries to inject malicious VBScript via a crafted update response. The exploit leverages the serv_update.vbs script and SQL Server Agent jobs using ActiveScripting, executing untrusted code with system privileges. Attackers can bypass authentication by manipulating the update domain, leading to remote code execution without user interaction.
Enterprise & DIB Impact
DIB organizations and enterprises relying on Ozols Grupa's software face heightened risk of data exfiltration, operational disruption, and persistent access. Compromised update channels could allow nation-state actors or cybercriminals to infiltrate critical infrastructure or financial systems, leveraging the high-severity flaw for long-term exploitation.
Recommended Actions
- Update to version 1.1.1233 immediately
- disable automatic update functionality until patched
- monitor network traffic for unauthorized update domain communications
- restrict ActiveScripting execution in SQL Server Agent jobs
- and audit all untrusted scripts like serv_update.vbs for anomalies
Need Help Assessing Your Exposure?
Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.
Schedule a ConsultationFull security advisory on 247alerts.net →