enterprise-security-vulnerability2.815 min read "Check Point Issues Emergency Fix for VPN Zero-Day Amid Rising Attacks"
Check Point has issued a warning about a zero-day vulnerability (CVE-2024-24919) in its Network Security gateway products, which has been actively exploited. The flaw, with a CVSS score of 7.5, affects various Quantum and CloudGuard products and allows attackers to read information on Internet-connected gateways with remote access VPN or mobile access enabled. Hotfixes are available for affected versions. The vulnerability has been exploited since April 30, 2024, allowing unauthorized actors to extract password hashes and Active Directory data, leading to potential lateral movement within networks.
1 year ago•Source: The Hacker News