HomeSecurityFortinet: Vulnerability used to install remote access software

Fortinet: Vulnerability used to install remote access software

A critical security vulnerability affecting Fortinet FortiClient EMS , now fixed, is being exploited by malicious hackers to software remote access (e.g. AnyDesk and ScreenConnect) on target devices.

Fortinet FortiClient EMS vulnerability

This is the vulnerability CVE-2023-48788 (CVSS score: 9.3), a SQL injection vulnerability that allows attackers to execute unauthorized code or commands by sending specially crafted data packets.

Kaspersky , hackers targeted an Windows server that was exposed to the Internet and had two open ports connecting to the Fortinet FortiClient EMS.

See also: Fortinet vulnerabilities allow hackers to execute code remotely

" The targeted company uses this technology to allow employees to download specific policies to their corporate devices, providing them with secure access to the Fortinet VPN ," the company said

Further analysis of the attack showed that the attackers exploited the CVE-2023-48788 vulnerability to gain initial access, then installed a ScreenConnect executable to gain remote access to the compromised computer.

"After the initial installation, the attackers began uploading additional payloads to the compromised system to initiate lateral movement activities and explore network resources, obtain credentials, perform defense evasion techniques, and create persistence via the AnyDesk," Kaspersky said.

Some other tools were also identified in this attack:

  • webbrowserpassview.exe : a password recovery tool that reveals passwords stored in Internet Explorer (version 4.0 – 11.0), Mozilla Firefox (all versions), and Google Chrome, Safari, and Opera
  • Mimikatz : a tool that extracts stored passwords
  • netpass64.exe : a password recovery tool
  • netscan.exe : a network scanner

See also: DEEPDATA framework exploits Fortinet vulnerability to steal VPN credentials

The attackers are believed to have targeted various companies in Brazil, Croatia, France, India, Indonesia, Mongolia, Namibia, Peru, Spain, Switzerland, Turkey and the United Arab Emirates, using different ScreenConnect subdomains (e.g. infinity.screenconnect[.]com).

remote access

Kaspersky said it detected further attempts to exploit the Fortinet CVE-2023-48788 vulnerability on October 23, 2024. This time, an attempt was made to exploit a PowerShell script hosted on a webhook[.]site domain in order to “collect responses from vulnerable targets” during a scan of a system vulnerable to the bug.

The above shows that applying the latest updates is critical for the security of systems. Failure to apply Fortinet patches allows attackers to exploit vulnerabilities to cause damage or gain access to sensitive data.

Additionally, failure to apply updates could potentially functionality system. Attacks that exploit vulnerabilities can cause serious disruptions, which may include data loss or inability to access services.

See also: Fortinet: Vulnerability in FortiManager used in attacks

In addition to updating FortiClient EMS, it is important to use strong and unique passwords for administrative accounts. This can help prevent account compromise through brute force or dictionary attacks.

Using an intrusion protection system (IPS) can also help detect and prevent RCE attacks. systems monitor the network for suspicious activity and can block communication to and from IP addresses known to be involved in RCE attacks.

Finally, implementing the principles of least privilege can reduce the likelihood of a successful RCE attack. This means that users and administrators should only have the privileges they need to perform their tasks and no more.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS