CVE-2024-3400
ID: 65b47360-7670-5e18-8ae5-a914375e5512
STIX ID: report--65b47360-7670-5e18-8ae5-a914375e5512
Feed Name: Arctic Wolf Blog
On April 12, 2024 Palo Alto Networks disclosed CVE-2024-3400 (CVSS 10.0), a zero-day remote code execution vulnerability in GlobalProtect (PAN-OS 10.2, 11.0, 11.1) actively exploited in the wild; the actor UTA0218 installed a custom Python backdoor called UPSTYLE on compromised firewalls, used those devices to stage further tooling, moved laterally, and exfiltrated credentials and files. Palo Alto Networks planned hotfix releases by April 14, 2024 and recommended temporary mitigations including enabling Threat Prevention signature 95187, applying vulnerability protection on GlobalProtect interfaces, or temporarily disabling device telemetry until patches are applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
