The flaw can be exploited remotely via crafted requests for remote code execution (RCE) and does not require authentication. The observed execution pattern suggests that threat actors used FortiClient’s own management pathway to push malicious PowerShell commands to managed endpoints in a way that resembled legitimate management operations. The information-stealing malware deployed in these attacks targets Chrome, Microsoft Edge, Firefox, and other Chromium and Gecko-based browsers for credential, cookie, and autofill data theft. The harvested data is exfiltrated over HTTP.
| Vendor | Product | Versions |
|---|---|---|
| fortinet | forticlientems | 7.4.5 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| fortinet | forticlient | cert_advisory | 90% |
Updated description with detailed exploitation methods and added new IoCs and tags related to the information-stealing malware.
Updated description to include active exploitation context and added new CWE IDs and tags related to ransomware and cyber-espionage.
Updated CVSS from 9.1 to 9.8 and noted that the patch is now null.
Added affected version 7.4.7 and updated patch available to 7.4.7, along with a new tag for Zero Trust Network Access (ZTNA).
Updated affected versions to include 7.4.6, added patch version 7.4.6, and included a new tag for elevation of privileges.
Updated description with more technical detail, added affected version 7.4.7, and included new tags and IoCs.
Updated patch availability to 'hotfix' and added new tags related to in-the-wild exploitation and government advisory.
Added affected version 7.2 and noted that the patch available is now null as hotfixes are provided.
Updated description with more technical details, added new tags, and confirmed patch version 7.4.7.
Updated description with details on the zero-day exploitation and added relevant tags.
Updated CVSS from 9.1 to 9.8, added affected version 7.4.6, and confirmed patch available as 7.4.7.
Added affected version 7.4.6, confirmed active exploitation, and noted patch availability in version 7.4.7.
Initial creation