• XSS.stack #1 – первый литературный журнал от юзеров форума

FortiOS Flaw Exploited as Zero-Day in Attacks on Government and Organizations

dP3ter

HDD-drive
Пользователь
Регистрация
23.11.2022
Сообщения
39
Реакции
14
A zero-day vulnerability in FortiOS SSL-VPN was exploited by "unknown actors" :cool: in attacks targeting the government and other government-related organizations.

It's a heap-based buffer overflow flaw that allows hackers to remotely execute malicious code.
Fortinet didn’t disclose the vulnerability until December 12, when it warned that the vulnerability was under active exploit against at least one of its customers.

Sources:
 
Этот экслойт очень сложный в своем исполнение, на практике это почти не реально
 
Official statement from Fortinet about CVEs is always:
¯\_(ツ)_/¯

Get popcorn and check their "statements" from 2018 until now.
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх