
About Remote Code Execution - ViPNet Client (BDU:2026-09885) vulnerability. The ViPNet Client software suite is designed to protect corporate users' workstations by providing secure data exchange over IP networks, controlling the network activity of applications and operating system components, and performing personal firewall functions (in the ViPNet Client for Windows version). ViPNet Client operates within the ViPNet network ecosystem and integrates with products from the ViPNet Network Security product line. A vulnerability involving a violation of the data protection mechanism (CWE-693) allows an attacker who has gained control of a host running ViPNet Administrator to distribute malicious updates to hosts running ViPNet Client. According to the vendor bulletin, the attackers' objectives include compromising the integrity of the operating environment, escalating privileges, and executing arbitrary code on the system.
👾 On July 16, experts from Positive Technologies reported the exploitation of this vulnerability in the wild. During the attacks, the threat actor transmitted a container file (.ctl) containing the malicious wtsapi32.dll library using the built-in functionality of the MFTP transport protocol. The malicious library was loaded by the Itcsrvup64.exe executable (a component of the ViPNet software update service) using the DLL Hijacking technique and written to the file system through a Path Traversal technique. The research describes various types of malware deployed by the threat actors on compromised hosts, including tools that operate as proxy servers to redirect network traffic, load additional DLL libraries into process memory and execute them, clear InfoTeCS logs, and collect system information (processes, network connections, installed software, etc.). The report also mentions the previously described Donnect loader and ShadowRelay backdoor. According to available data, the attack campaign was active from at least June 1 to July 14, 2026, and affected at least eight organizations.
⚙️ To remediate the vulnerability, certified builds must be updated to ViPNet Client 4 version 4.5.3 (build 65211) or later. For release builds, ViPNet Client 4 must be updated to version 4.5.5 (build 24749) or later. The vendor also recommends updating ViPNet Administrator 4 to version 4.6.11.5114.
🛠 No signs of publicly available exploits for this vulnerability have been observed so far.
