Malicious actors have been exploiting a high-severity Check Point Remote Access VPN zero-day since at least April 30 , stealing Active Directory data required to move laterally across victims' networks in successful attacks .
See also: Google Chrome: Fourth zero-day patched in a month

Check Point warned customers on Monday that attackers are targeting their security gateways using old local VPN accounts with insecure password-only authentication.
The company subsequently discovered that hackers were exploiting an information disclosure flaw (tracked as CVE-2024-24919) in these attacks and released hotfixes to help customers block exploit attempts against vulnerable CloudGuard Networks, Quantum Maestro, Quantum Scalable Chassis, Quantum, and Quantum Spark devices.
After applying the newly released hotfix, all login attempts using weak credentials and authentication methods will be automatically blocked and logged. Check Point also provides additional information about CVE-2024-24919 and the hotfix in this support document.
Exploited in attacks since April
While Check Point disclosed that attacks targeting the zero-day flaw in its VPN began around May 24, cybersecurity firm Mnemonic warned today that it had observed exploitation attempts in some of its customer environments since April 30.
See also: PoC exploit released for RCE zero-day on DIR-X4860 routers
The company added that the vulnerability is "highly critical" because it is easy to exploit remotely, as it does not require user interaction or privileges on compromised Check Point security gateways with Remote Access VPN and Mobile Access.

Hackers have been spotted extracting ntds.dit, a database that stores Active Directory data on users, groups, security descriptors, and password hashes, from compromised clients within 2-3 hours of logging in as a local user.
The Check Point VPN zero-day vulnerability has also been exploited to extract information that allowed attackers to move laterally into the victim's network and misuse Visual Studio to funnel malicious traffic.
Mnemonic advises Check Point customers to immediately update affected systems to the patch and remove any local users on vulnerable security gateways.
Administrators are also advised to rotate passwords/accounts for LDAP connections from the gateway to Active Directory, perform post-patch searches of logs for signs of compromise such as anomalous behavior and suspicious connections, and, if available, update the Check Point IPS signature to detect exploit attempts.
See also: Microsoft: Fixes zero-day used to distribute QakBot (Qbot)
What are the best practices for protecting against zero-days?
Regularly updating and upgrading software is critical to protecting against zero-day bugs, such as Check Point VPN. Using a strong and up-to-date antivirus software can help detect and prevent malware that exploits zero-day vulnerabilities. Implementing security policies that restrict user access rights can reduce the risk of exploiting vulnerabilities. Regularly educating and raising awareness of users about threats and best practices can help prevent attacks that exploit human error. Using sandboxing technologies can limit the impact of a zero-day bug by isolating the execution of the malware from the rest of the system. Finally, monitoring and analyzing network traffic for anomalies can help in the early detection and response to attacks that exploit zero-day vulnerabilities.
Source: bleepingcomputer
