Exploit code for Palo Alto Networks zero-day now public
ID: ee81fc02-78c7-5d74-b785-d81dcc45356e
STIX ID: report--ee81fc02-78c7-5d74-b785-d81dcc45356e
Feed Name: The Register (Security)
A maximum-severity vulnerability (CVE-2024-3400) in Palo Alto Networks' PAN-OS GlobalProtect telemetry service allows unauthenticated command injection leading to remote code execution; public proof-of-concept exploits were released shortly after vendor hotfixes and the flaw has been observed in zero-day exploitation. Researchers demonstrated an exploit chain involving file-creation via a crafted SESSID cookie and command injection, and disabling telemetry is no longer a reliable mitigation; Shadowserver reports ~156,000 public GlobalProtect appliances and CISA added the issue to its Known Exploited Vulnerabilities list, prompting urgent patching and available Threat Prevention signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
