ZeroHour
The Recordpublished ()ingested

CISA warns of exploited Fortinet bugs as Microsoft issues its biggest Patch Tuesday in years

criticalVulnerability exploited in the wildimportance 60CVE-2024-55591CVE-2025-21333CVE-2025-21334

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-55591
Unauthenticated Super-Admin Bypass in Fortinet FortiOS and FortiProxy

CVE-2024-55591 is an authentication bypass (CWE-288) in the Node.js websocket module of Fortinet FortiOS and FortiProxy that lets a remote, unauthenticated attacker gain super-admin privileges via crafted websocket requests. It affects FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12, and is trivially triggerable from the network with no user interaction given network access to the management/websocket interface. Successful exploitation gives full super-admin control of the appliance, which attackers can use to pivot, create persistent access, and deploy ransomware. Any organization running the affected FortiOS or FortiProxy versions, especially with admin interfaces reachable from the internet, is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14, and multiple ransomware crews (reported as Gunra, SuperBlack, and Mora_001) are actively exploiting it.

Do: Upgrade all affected systems beyond the vulnerable ranges — FortiOS later than 7.0.16 and FortiProxy later than 7.0.19 / 7.2.12 — following Fortinet's advisory, or apply the vendor's mitigations where upgrades are not possible (per CISA KEV instructions). Restrict access to the admin/websocket interface from the internet, and hunt for unauthorized super-admin accounts and suspicious websocket connections, since ransomware operators are actively exploiting this flaw. Verify device versions and audit logs for signs of compromise before and after patching.

9.898% KEV ransomware
  • Fortinet FortiOS 7.0.0 through 7.0.16
  • Fortinet FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12
large≈48,000+ internet-exposed Fortinet devices per public scans, out of an installed base in the hundreds of thousands
CVE-2025-21333
+1 in the same advisory: …21334
Actively Exploited Heap Overflow in Windows Hyper-V VSP Enables Privilege Escalation

CVE-2025-21333 is a heap-based buffer overflow (CWE-122) in the Windows Hyper-V NT Kernel Integration VSP, which Microsoft classifies as an elevation of privilege vulnerability. An attacker who already has low-privileged access to an affected system can trigger the overflow in this virtualization service provider component to gain higher privileges on the host, with high impact on confidentiality, integrity and availability (CVSS 3.1 score 7.8, local attack vector, no user interaction required). The flaw affects Windows 10 21H2 and 22H2, Windows 11 22H2, 23H2 and 24H2, Windows Server 2022 23H2, and Windows Server 2025. Microsoft patched it in the January 2025 Patch Tuesday release (part of a batch of eight zero-days), and it was exploited as a zero-day before the patch was available: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14 with ransomware use listed as unknown. A public proof-of-concept is available via Exploit-DB, so defenders should treat in-the-wild exploitation as confirmed.

Do: Apply Microsoft's January 2025 Patch Tuesday security updates (released 2025-01-14) to all systems running Windows 10 21H2/22H2, Windows 11 22H2/23H2/24H2, Windows Server 2022 23H2 or Windows Server 2025, prioritizing this KEV-listed, actively exploited zero-day; where updates cannot be applied, follow vendor mitigations or discontinue use of the affected versions per CISA's required action. Because the attack requires local access, prioritize patching multi-user hosts, VDI and terminal servers, and during threat hunting review endpoints for signs that malware or low-privileged users previously escalated privileges via the Hyper-V VSP component.

7.810% KEV PoC
  • microsoft Windows 10 21H2
  • microsoft Windows 10 22H2
  • microsoft Windows 11 22H2
  • +4 more
mass≈hundreds of millions of Windows endpoints potentially affected (affected versions span most of the Windows 10/11 install base), though only systems with…
Full article759 words · extracted from therecord.media · click to collapse

The federal government and multiple cybersecurity firms warned of a zero-day vulnerability in FortiGate firewalls that hackers are actively exploiting. 

In a sign of the bug’s severity, the Cybersecurity and Infrastructure Security Agency (CISA) ordered all federal civilian agencies to patch the vulnerability by January 21 — one of the shortest deadlines it has ever issued. 

Fortinet said in an advisory that the bug is being exploited in the wild but did not say how many customers have been impacted. The company said threat actors attacking organizations with the vulnerability are creating administrative accounts on targeted devices and changing settings related to firewall policies. 

Cybersecurity firm Arctic Wolf reported seeing the vulnerability being used by hackers before Fortinet disclosed the bug. The company said in early December it saw a campaign targeting FortiGate firewall devices that had interfaces exposed on the public internet, noting that a “zero-day vulnerability is highly probable.”

“The victimology in this campaign was not limited to any specific sectors or organization sizes. The diversity of victim organization profiles combined with the appearance of automated login/logout events suggests that the targeting was opportunistic in nature rather than being deliberately and methodically targeted,” the company said. 

Benjamin Harris, CEO of cybersecurity firm watchTowr, told Recorded Future News that the bug is “the latest vulnerability in a mission-critical appliance (that provides security-focused capabilities) to bear the hallmarks of zero-day exploitation by an APT group.” 

Harris added that it was important the public knew how severe the situation is, noting that “if rapid reaction measures have not already been taken, administrators should be jumping straight to looking for the signs of compromise outlined by Fortinet within their advisory.”

Incident responders at Rapid7 said they have seen incidents “consistent with scanning or reconnaissance activity and not exploitation.”

Old Fortinet bugs and Microsoft’s big Tuesday

Concern about the bug, tracked as CVE-2024-55591, emerged as other cybersecurity experts expressed alarm about an older zero-day vulnerability from 2022 affecting FortiGate firewalls. Prominent cybersecurity researcher Kevin Beaumont said a group of hackers this week released the configurations for about 15,000 FortiGate firewalls. 

Beaumont confirmed the legitimacy of the leak and noted that the stolen data contains usernames, passwords, device management certificates and firewall rules. 

“I’ve done incident response on one device at a victim org, and exploitation was indeed via CVE-2022–40684 based on artefacts on the device,” he said, referring to the older bug.

“Even if you patched back in 2022, you may still have been exploited as the configs were dumped years ago and only just released — you probably want to find out when you patched this vuln. Having a full device config including all firewall rules is… a lot of information.”

Rapid7 also looked into this issue and confirmed that some of the leaked data originated from 2022 incidents where customer firewalls were compromised.

The Fortinet bugs come after the first Patch Tuesday of 2025, where Microsoft unveiled 157 CVEs — the largest number of CVEs patched across any Patch Tuesday release since 2017, Tenable senior staff research engineer Satnam Narang said. 

Eight of the Microsoft bugs are zero-days, including three that were exploited and five that were publicly disclosed ahead of Patch Tuesday.

Of the bugs released, CISA ordered federal agencies to patch CVE-2025-21333 and CVE-2025-21334 by February 4. 

The bugs affect a highly-technical Microsoft product called Windows Hyper-V NT Kernel Integration VSP. Hyper-V is embedded in the Windows 11 operating systems and is used for a variety of security tasks.

Multiple cybersecurity experts backed CISA’s assessment that CVE-2025-21333 and CVE-2025-21334 are the vulnerabilities IT workers should start with when looking at Microsoft’s Patch Tuesday release. 

“Organizations relying on Hyper-V, including data centers, cloud providers, enterprise IT environments, and development platforms, are at risk,” said Mike Walters, co-founder of cybersecurity firm Action1, who warned that the bugs could be combined with others to increase their impact. . 

“Potential impacts include: Accessing and manipulating virtual machines on the host. Stealing sensitive data or credentials. Moving laterally within the network to target other systems. Disrupting critical services by modifying configurations or deploying malicious code.”

In addition to the Microsoft bugs, several other companies released notices about vulnerabilities including Ivanti, Cisco, Chrome, SAP and more.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-warns-fortinet-bugs-microsoft-patch-tuesday