Serious PostgreSQL flaw exploited in US Treasury zero-day attack

Security researchers have uncovered a significant zero-day vulnerability in PostgreSQL, which is now believed to have played a pivotal role in the cyber breach of the US Treasury last December. This revelation comes from Stephen Fewer, a principal security researcher at Rapid7, who was investigating the BeyondTrust vulnerability identified as CVE-2024-12356.

Discovery of Vulnerabilities

During their research, Rapid7’s team identified a novel zero-day vulnerability in PostgreSQL, designated as CVE-2025-1094. Fewer stated, “In every scenario we tested, a successful exploit for CVE-2024-12356 had to include exploitation of CVE-2025-1094 in order to achieve remote code execution.” This finding was shared in a detailed blog post outlining the attack methodology.

Initially, the breach of the US Treasury was attributed solely to the command injection vulnerability CVE-2024-12356 within the BeyondTrust Remote Support SaaS platform. However, the recent research indicates that exploiting CVE-2024-12356 necessitated the prior exploitation of CVE-2025-1094.

Although BeyondTrust issued a patch for CVE-2024-12356 in December 2024, which effectively blocked the exploitation of both vulnerabilities, it did not address the underlying cause of CVE-2025-1094. This left it as a zero-day vulnerability until Rapid7 reported it to PostgreSQL.

The implications of this exploit are serious, as it is believed that Chinese hackers were able to gain remote access to multiple workstations within the US Treasury, potentially compromising unclassified documents. The specifics regarding the documents accessed and the number of workstations involved remain undisclosed.

This incident is part of a broader pattern of cyber attacks linked to Chinese state-sponsored actors, including the notorious Salt Typhoon breaches, which have allowed unauthorized access to sensitive communications among US citizens.

Cloud & Cyber Security Expo is one of the largest IT security events in Europe. Don’t miss the chance to build partnerships and discover solutions to protect your business. Tickets are free for non-vendors!

Tech Optimizer
Serious PostgreSQL flaw exploited in US Treasury zero-day attack