Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-20481 | Unauthenticated Remote Access VPN DoS in Cisco ASA and FTD Software CVE-2024-20481 is a denial-of-service vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software, caused by resource exhaustion (CWE-772). An unauthenticated, remote attacker can trigger it by sending a large number of VPN authentication requests to an affected device, consistent with the large-scale VPN brute-force activity Cisco Talos has documented. A successful attack exhausts device resources and causes a denial of service of the RAVPN service, potentially requiring a device reload to restore VPN service, though non-VPN functionality is unaffected. Only ASA and FTD devices with the RAVPN service enabled are affected. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-24, and trade press reports Cisco issued urgent fixes for this actively exploited bug. Do: Apply the fixed ASA/FTD Software releases specified in Cisco's advisory for CVE-2024-20481, or apply Cisco's documented mitigations (such as rate-limiting/throttling VPN authentication attempts) if patching is not immediately possible. Check RAVPN devices for bursts of failed or unusual VPN authentication requests consistent with brute-forcing, and restrict or disable internet-exposed RAVPN where it is not needed. Per CISA KEV guidance, apply vendor mitigations or discontinue use of the product if mitigations are unavailable. | 5.8 | 16% | KEV |
| masshundreds of thousands of internet-exposed Cisco ASA/FTD appliances, of which the RAVPN-enabled subset is directly vulnerable | |
| CVE-2024-37383 | Cross-Site Scripting in Roundcube Webmail via SVG animate attributes CVE-2024-37383 is a cross-site scripting vulnerability (CWE-79) in Roundcube Webmail caused by insufficient handling of SVG 'animate' attributes when HTML email content is rendered. An attacker triggers it by sending a crafted HTML email containing a malicious SVG animate element; when the recipient views the message in Roundcube, attacker-controlled JavaScript executes in the context of the victim's webmail session. Successful exploitation allows theft of session cookies and credentials, access to mailbox contents, sending mail as the victim, or redirection to phishing pages, and has been used in campaigns that steal credentials and email. All Roundcube Webmail deployments before 1.5.7 and 1.6.x before 1.6.7 are affected, including Roundcube packages shipped with Debian; because the attack requires only viewing a malicious email, any exposed webmail user is a potential victim. The flaw is under active exploitation: unknown threat actors have used it in phishing campaigns, it carries an EPSS of 73.3%, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-24. Do: Upgrade Roundcube to version 1.5.7 or 1.6.7 (or later) immediately; Debian users should install the updated roundcube package from their repository. Organizations subject to CISA BOD 22-01 must apply vendor mitigations or discontinue use per the KEV entry. Review webmail logs for phishing emails containing SVG animate elements and investigate for credential theft or anomalous mailbox activity. | 6.1 | 73% | KEV |
| masslikely millions of webmail users across hundreds of thousands of deployed instances, with tens of thousands of instances internet-exposed | |
| CVE-2024-38094 | Authenticated deserialization RCE in Microsoft SharePoint Server CVE-2024-38094 is a deserialization of untrusted data flaw (CWE-502) in on-premises Microsoft SharePoint Server, rated 7.2 (high) on CVSS 3.1 and classified by Microsoft as a remote code execution vulnerability. The CVSS vector (AV:N/AC:L/PR:H/UI:N) indicates the attack is network-reachable but requires an attacker who already holds high-privileged access, such as site collection or farm administrator credentials, to submit maliciously crafted serialized data to the server. Successful exploitation yields remote code execution on the SharePoint server with high impact to confidentiality, integrity, and availability, giving attackers a foothold for follow-on activity such as ransomware deployment. Any organization running on-premises SharePoint Server is potentially affected, while SharePoint Online in Microsoft 365 is a separate cloud service. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-10-22 with known ransomware use, and the EPSS of 50.9% (99th percentile) signals a high probability of continued exploitation, although no public proof-of-concept is known. Do: Apply Microsoft's vendor-supplied mitigations and security updates for SharePoint Server as soon as possible; CISA's required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Limit internet exposure of SharePoint front-ends, review high-privileged site and farm administrator accounts for compromise or unusual activity, and prioritize patching given the confirmed ransomware use. No public PoC is known, but the 50.9% EPSS and KEV listing indicate attackers are actively working this flaw. | 7.2 | 51% | KEV ransomware |
| largeon the order of tens of thousands of internet-exposed SharePoint Server deployments (roughly 10k-100k servers) | |
| CVE-2024-38812 +1 in the same advisory: …38813 | Unauthenticated RCE in VMware vCenter Server via DCERPC heap overflow VMware vCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its implementation of the DCERPC protocol. A remote attacker with network access to vCenter Server can trigger the flaw by sending a specially crafted network packet; no credentials, privileges, or user interaction are required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N). Successful exploitation can lead to remote code execution with high impact on confidentiality, integrity, and availability of the vCenter host. Affected products are VMware vCenter Server and VMware Cloud Foundation deployments, with the exact vulnerable version ranges specified in the Broadcom/VMware advisory. The flaw is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2024-11-20, EPSS estimates a 54.6% probability of exploitation within 30 days (99th percentile), and related reporting describes PRC hackers using the BRICKSTORM backdoor in campaigns involving actively exploited VMware vCenter flaws; no public proof-of-concept is known. Do: Apply the patched vCenter Server / VMware Cloud Foundation releases issued by Broadcom per the vendor advisory, and because reporting indicates the fix was re-issued, verify the latest patched build is actually installed rather than an earlier, possibly incomplete one. Prioritize patching internet-facing vCenter instances and restrict network access to the vCenter management interface in the interim. Per the CISA KEV required action, apply vendor mitigations or discontinue use if mitigations are unavailable, and hunt for signs of post-exploitation (e.g., BRICKSTORM activity) given confirmed in-the-wild exploitation. | 9.8 | 55% | KEV |
| largeseveral thousand internet-exposed vCenter instances per public scans; on the order of 100,000+ total vCenter deployments worldwide (estimate) | |
| CVE-2024-4947 | V8 Type Confusion in Google Chrome Actively Exploited by Lazarus Group CVE-2024-4947 is a type-confusion flaw (CWE-843) in the V8 JavaScript engine of Google Chrome, rated High by Chromium with a CVSS 3.1 score of 9.6. An attacker triggers it by luring a user to a crafted HTML page, causing V8 to misinterpret object types and enabling execution of arbitrary code inside the Chrome sandbox. Exploitation of the V8 bug alone keeps the attacker sandboxed, but it is a typical first stage of a browser exploit chain and can be paired with sandbox-escape techniques for broader system access. All Google Chrome installations prior to 125.0.6422.60 are affected, as are Fedora's packaged builds of Chrome/Chromium carrying the vulnerable V8 code. The vulnerability was added to CISA's KEV on 2024-05-20, has a public PoC referenced in Google's issue tracker, and public reporting ties its in-the-wild use to the North Korean Lazarus Group, which deployed the FudModule rootkit against infected Chrome users. Do: Upgrade Google Chrome to 125.0.6422.60 or later on all endpoints, and install the updated chromium packages published for Fedora, prioritizing this patch because the flaw is CISA KEV-listed with a mandatory mitigation deadline. Because Lazarus Group is exploiting this in the wild via crafted web pages, review endpoint telemetry for suspicious browser-borne activity and warn users against opening links from untrusted or decoy game/job-lure sites. | 9.6 | 15% | KEV PoC |
| masson the order of billions of Chrome installations (Chrome is the world's dominant desktop browser with roughly 65% market share and a multi-billion active… |
Full article904 words · extracted from helpnetsecurity.com · click to collapse

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:
Fortinet releases patches for publicly undisclosed critical FortiManager vulnerability
In the last couple of days, Fortinet has released critical security updates for FortiManager, to fix a critical vulnerability that is reportedly being exploited by Chinese threat actors.
VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812)
Broadcom has released new patches for previously fixed vulnerabilities (CVE-2024-38812, CVE-2024-38813) in vCenter Server, one of which hasn’t been fully addressed the first time and could allow attackers to achieve remote code execution.
Roundcube XSS flaw exploited to steal credentials, email (CVE-2024-37383)
Attackers have exploited an XSS vulnerability (CVE-2024-37383) in the Roundcube Webmail client to target a governmental organization of a CIS country, Positive Technologies (PT) analysts have discovered.
The Internet Archive breach continues
Cybersecurity troubles are not over for the Internet Archive (IA), the nonprofit organization behind the popular digital library site: after the recent DDoS attacks, defacement and data breach, an email sent via its Zendesk customer service platform has shown that some of its IT assets remain compromised.
Exploited: Cisco, SharePoint, Chrome vulnerabilities
Threat actors have been leveraging zero and n-day vulnerabilities in Cisco security appliances (CVE-2024-20481), Microsoft Sharepoint (CVE-2024-38094), and Google’s Chrome browser (CVE-2024-4947).
The future of cyber insurance: Meeting the demand for non-attack coverage
In this Help Net Security interview, Michael Daum, Head of Global Cyber Claims for Allianz Commercial, discusses the significant rise in cyber claims in 2024, driven by an increase in data breaches and ransomware attacks.
Enhancing national security: The four pillars of the National Framework for Action
In this Help Net Security interview, John Cohen, Executive Director, Program for Countering Hybrid Threats at the Center for Internet Security, discusses the four pillars of the National Framework for Action, emphasizing how these measures can combat the exploitation of technology and social media by threat actors.
Effective strategies for measuring and testing cyber resilience
In this Help Net Security interview, Detective Superintendent Ian Kirby, CEO of the National Cyber Resilience Centre Group (NCRCG), discusses the emerging cyber threats and strategies organizations can use to increase cyber resilience.
Myths holding women back from cybersecurity careers
In this Help Net Security interview, Dr Kathryn Jones, Head of School, Computer Science and Informatics at Cardiff University, discusses the challenges and misconceptions that deter women from pursuing careers in cybersecurity.
Building secure AI with MLSecOps
In this Help Net Security interview, Ian Swanson, CEO of Protect AI, discusses the concept of “secure AI by design.”
Aranya: Open-source toolkit to accelerate secure by design concepts
SpiderOak launched its core technology platform as an open-source project called Aranya. This release provides the same level of security as the company’s platform, which is already in use by the Department of Defense.
Argus: Open-source information gathering toolkit
Argus is an open-source toolkit that simplifies information gathering and reconnaissance.
Achieving peak cyber resilience
Countering cyberthreats like ransomware is an inescapable aspect of today’s business operating environment. No organization is immune.
How to fend off a quantum computer attack
In this Help Net Security video, IEEE member Marc Lijour explains quantum computing and offers insight into how to fend off a quantum computer attack.
Should the CISOs role be split into two functions?
84% of CISOs believe the role needs to be split into two functions – one technical and one business-focused, to maximize security and organizational resilience, according to Trellix.
What’s more important when hiring for cybersecurity roles?
When building a cybersecurity team, you likely asked yourself, “Should I focus on certifications or real-world skills?”
Hackers are finding new ways to leverage AI
AI adoption and integration has continued its rapid momentum within the hacking community, according to Bugcrowd.
Evolving cloud threats: Insights and recommendations
In this Help Net Security video, Austin Zeizel, Threat Intelligence Consultant at IBM X-Force, discusses the cloud threat landscape.
IT security and government services: Balancing transparency and security
Whether residents are accessing public records or leveraging self-service features, it is essential that local and state governments provide technology that enables agency and transparency. But this is only successful if that technology provides ease of access.
Phishing scams and malicious domains take center stage as the US election approaches
Phishing scams aimed at voters, malicious domain registrations impersonating candidates, and other threat activity designed to exploit unassuming victims take center stage as the US election approaches, according to Fortinet.
Evolving cybercriminal tactics targeting SMBs
In this Help Net Security video, David Langlands, Chief Security Officer at Todyl, discusses these evolving cyber threats.
Cybersecurity jobs available right now: October 23, 2024
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.
How to enable Safe Browsing in Google Chrome on Android
To safeguard your data, Google Chrome uses Safe Browsing to protect you from: harmful websites and extensions, malicious or intrusive advertisements, malware, phishing attacks, and social engineering threats.
Whitepaper: Securing GenAI
The ultimate guide to AI security: key AI security risks, vulnerabilities and strategies for protection. 61% of companies use AI, but few secure it. This whitepaper covers the key AI risks being overlooked from LLMs to RAG.
New infosec products of the week: October 25, 2024
Here’s a look at the most interesting products from the past week, featuring releases from Fastly, IBM, Ivanti, Kusari, and Nucleus Security.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/10/27/week-in-review-fortinet-patches-critical-fortimanager-0-day-vmware-fixes-vcenter-server-rce/