Accessibility Statement Skip Navigation
  • Back to Global Sites
  • +972-77-2005042
  • Blog
  • Journalists
  • GDPR
  • Send a Release
PR Newswire: news distribution, targeting and monitoring
  • News
  • Products
  • Contact
  • Hamburger menu
  • PR Newswire: news distribution, targeting and monitoring
  • Send a Release
    • Telephone

    • +972-77-2005042 from 8 AM - 11 PM IL

    • Contact
    • Contact

      +972-77-2005042
      from 8 AM - 11 PM IL

  • When typing in this field, a list of search results will appear and be automatically updated as you type.

  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR

Pentera Labs Researchers Discover Zero-Day CVE in Fortinet's FortiClient VPN Service


News provided by

Pentera

14 Nov, 2024, 16:00 IST

Share this article

Share toX

Share this article

Share toX

CVE may affect millions of devices that utilize FortiClientWindows version 7.4.0 as well as previous versions, and requires immediate patching

BOSTON, Nov. 14, 2024 /PRNewswire/ -- Pentera, the leader in Automated Security Validation, today announced the discovery of a Zero-Day vulnerability by its Pentera Labs research team. Researchers uncovered a high severity CVE that can lead to the escalation to SYSTEM privileges, establishment of persistence within the system, and deletion of log entries.

The vulnerability was reported to Fortinet by Security Researcher Nir Chako in March 2024 and responsibly disclosed to the Fortinet team. The vulnerability has been released now under CVE-2024-47574 with a patch. The CVE impacts all users of FortiClientWindows [version 7.4.0 and previous], as well as previous versions. Pentera Labs' technical review of the vulnerability can be found here.

As the primary solution to secure remote connections, VPNs are among the most popular targets for threat actors. According to ZScaler's 2023 VPN Risk Report, 45% of organizations confirmed experiencing at least one attack that exploited VPN vulnerabilities in the previous 12 months, with one in three becoming victim of VPN-related ransomware attacks.

CVE-2024-47574 is an improper access control vulnerability in FortiClient that allows an authenticated low-privileged threat actor direct access to tamper with the service configuration, alter some registry keys of the service and delete sensitive log files.

"This research is a textbook example of how Pentera is able to test and validate against the latest attack techniques. The Pentera Labs team is made up of the most experienced white hat hackers who research the entire enterprise IT attack surfaces and probe the security controls protecting top enterprises," said Alex Spivakovsky, VP of Research at Pentera. "Our team consistently adds new attack vectors to our platform so that our customers are able to validate their security against the latest, most creative attacks threat actors are using today. Pentera Labs findings are fueling the engine that powers Pentera's platform, ensuring that our security validation is the most robust in the market in terms of both breadth and depth."

Sign up for our upcoming webinar with Pentera Labs' Researcher, Nir Chako, to learn more about the CVEs.

Updates and Mitigations

To remediate CVE-2024-47574 please visit Fortinet's Advisory site: https://www.fortiguard.com/psirt/FG-IR-24-199

About Pentera

Pentera is the market leader in Automated Security Validation, empowering companies to proactively stress-test all their cybersecurity controls against the latest cyber attacks. Pentera identifies true risk across the entire attack surface, guiding remediation to effectively reduce exposure. The company's security validation capabilities are essential for Continuous Threat Exposure Management (CTEM) operations. Thousands of security professionals around the world trust Pentera to close security gaps before threat actors can exploit them.

For more information, visit: pentera.io

Media contact for Pentera
Noam Hirsch
Senior PR Manager
[email protected]

SOURCE Pentera

Modal title

Also from this source

Pentera Appoints Hagit Ynon as Chief Financial Officer

Pentera Appoints Hagit Ynon as Chief Financial Officer

Pentera, the market leader in AI-powered security validation, today announced the appointment of Hagit Ynon as Chief Financial Officer. Hagit joins...

Pentera Introduces Adversarial AI Agent To Guide Offensive Security Practitioners

Pentera, the Exposure Validation Company, unveiled Pentera 8, a major platform release introducing AI-powered attacks controlled in natural language. ...

More Releases From This Source

Explore

High Tech Security

High Tech Security

Computer & Electronics

Computer & Electronics

Networks

Networks

Networks

Networks

News Releases in Similar Topics

Contact PR Newswire

  • +972-77-2005042
    from 8 AM - 11 PM IL

Global Sites

  • APAC
  • APAC - Traditional Chinese
  • Asia
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany

 

  • India
  • Indonesia
  • Israel
  • Italy
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland

 

  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921
Global Sites
  • Asia
  • Brazil
  • Canada
  • Csezh
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Israel
  • Italie
  • Mexico
  • Middle East
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States
+972-77-2005042
from 8 AM - 11 PM IL
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • Cookie Settings
Copyright © 2026 Cision US Inc.