Check Point has released hotfixes for a VPN zero-day vulnerability exploited in attacks to gain remote access to firewalls and attempt to breach corporate networks.
On Monday, the company first warned about a spike in attacks targeting VPN devices, sharing recommendations on how admins can protect their devices.
Later, it discovered the source of the problem, a zero-day flaw that hackers exploited against its customers.
Tracked as CVE-2024-24919, the high-severity information disclosure vulnerability enables attackers to read certain information on internet-exposed Check Point Security Gateways with remote Access VPN or Mobile Access Software Blades enabled.
The vendor says the process should take approximately 10 minutes, and a reboot is required.
After the hotfix is installed, login attempts using weak credentials and authentication methods will be automatically blocked, and a log will be created.
Hotfixes have been made available for end-of-life versions, too, but they must be downloaded and applied manually.
Check Point created a FAQ page with additional information about CVE-2024-24919, IPS signature, and manual hotfix installation instructions.
Those unable to apply the update are advised to enhance their security stance by updating the Active Directory password that the Security Gateway uses for authentication.
Check Point has created a remote access validation script that can be uploaded onto 'SmartConsole' and executed to review the results and take appropriate actions.
More information on updating the AD password and using the 'VPNcheck.
Sh' script are available on Check Point's security bulletin.
Google Chrome emergency update fixes 6th zero-day exploited in 2024.
Google fixes fifth Chrome zero-day exploited in attacks this year.
Hackers target Check Point VPNs to breach enterprise networks.
Google fixes eighth actively exploited Chrome zero-day this year.
QNAP QTS zero-day in Share feature gets public RCE exploit.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Wed, 29 May 2024 13:35:41 +0000