logo

Attackers exploiting a patched FortiClient EMS vulnerability in the wild

ID: 831d46ef-0958-542c-8aec-a7b834186779

STIX ID: report--831d46ef-0958-542c-8aec-a7b834186779

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2024-12-19

Date Updated: 2026-04-29

Author: Ashley Muñoz, Francesco Figurelli, Cristian Souza, Eduardo Ovalle, Areg Baghinyan

...
...

Kaspersky GERT investigated active exploitation of a known FortiClient EMS SQL injection (CVE-2023-48788) where attackers used the flaw to download and run remote access tools (ScreenConnect, AnyDesk), deploy credential-stealing utilities (Mimikatz, webbrowserpassview, netpass), and conduct lateral movement and persistence; the report provides TTP mapping, IoCs (hashes, domains, IPs), telemetry of multi-country scanning and exploitation, and recommends patching to versions 7.0.11+/7.2.3+ and deploying MDR/alerting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.