216.73.216.36

Attackers exploiting a FortiClient EMS vulnerability in the wild

· Published 19/12/2024 14:41 · Modified 19/12/2024 17:38

Export JSON

Essential information

Published
19/12/2024 14:41
Modified
19/12/2024 17:38
Tags
2024-12-19 CVE-2023-48788 anydesk credential-theft forticlient ems lateral movement mimikatz remote access screenconnect sql injection
Related entities
8 techniques (mitre)

Description

Kaspersky's GERT team identified an attack exploiting a patched vulnerability () in versions 7.0.1 to 7.0.10 and 7.2.0 to 7.2.2. The attackers used to infiltrate a company's network through an exposed Windows server. They deployed tools like and , performed network enumeration, credential theft, and defense evasion. The vulnerability allows unauthorized code execution via specially crafted data packets. Multiple threat actors have been observed exploiting this vulnerability globally, targeting various companies and consistently altering subdomains. The analysis highlights the importance of timely patching and implementing additional security controls to prevent such attacks.

External references