Tag Archives: PTESC

About Remote Code Execution - ViPNet Client (BDU:2026-09885) vulnerability

About Remote Code Execution - ViPNet Client (BDU:2026-09885) vulnerability

About Remote Code Execution - ViPNet Client (BDU:2026-09885) vulnerability. The ViPNet Client software suite is designed to protect corporate users' workstations by providing secure data exchange over IP networks, controlling the network activity of applications and operating system components, and performing personal firewall functions (in the ViPNet Client for Windows version). ViPNet Client operates within the ViPNet network ecosystem and integrates with products from the ViPNet Network Security product line. A vulnerability involving a violation of the data protection mechanism (CWE-693) allows an attacker who has gained control of a host running ViPNet Administrator to distribute malicious updates to hosts running ViPNet Client. According to the vendor bulletin, the attackers' objectives include compromising the integrity of the operating environment, escalating privileges, and executing arbitrary code on the system.

👾 On July 16, experts from Positive Technologies reported the exploitation of this vulnerability in the wild. During the attacks, the threat actor transmitted a container file (.ctl) containing the malicious wtsapi32.dll library using the built-in functionality of the MFTP transport protocol. The malicious library was loaded by the Itcsrvup64.exe executable (a component of the ViPNet software update service) using the DLL Hijacking technique and written to the file system through a Path Traversal technique. The research describes various types of malware deployed by the threat actors on compromised hosts, including tools that operate as proxy servers to redirect network traffic, load additional DLL libraries into process memory and execute them, clear InfoTeCS logs, and collect system information (processes, network connections, installed software, etc.). The report also mentions the previously described Donnect loader and ShadowRelay backdoor. According to available data, the attack campaign was active from at least June 1 to July 14, 2026, and affected at least eight organizations.

⚙️ To remediate the vulnerability, certified builds must be updated to ViPNet Client 4 version 4.5.3 (build 65211) or later. For release builds, ViPNet Client 4 must be updated to version 4.5.5 (build 24749) or later. The vendor also recommends updating ViPNet Administrator 4 to version 4.6.11.5114.

🛠 No signs of publicly available exploits for this vulnerability have been observed so far.

Statistics on 2024 trending vulnerabilities were featured in the OIC-CERT annual report

Statistics on 2024 trending vulnerabilities were featured in the OIC-CERT annual report

Statistics on 2024 trending vulnerabilities were featured in the OIC-CERT annual report. 🎉

🔹 The Organisation of Islamic Cooperation (OIC) is the largest and most influential official intergovernmental Muslim international organization. It currently unites 57 countries with a population of about 2 billion people. Russia is also a member of the OIC as an observer.

🔹 OIC-CERT is a computer incident response team and a subsidiary of the OIC. It brings together national CERTs from 27 countries, as well as 8 commercial organizations, including Positive Technologies.

➡️ The statistics on 2024 trending vulnerabilities that I prepared were published in the section highlighting Positive Technologies’ results (report size: 67.49 MB, p.229).

I’m glad my work contributed to promoting PT ESC and Positive Technologies among national CERTs and key decision-makers! 😉

На русском

Remote Code Execution - Scripting Engine (CVE-2024-38178)

Remote Code Execution - Scripting Engine (CVE-2024-38178)

Remote Code Execution - Scripting Engine (CVE-2024-38178). A vulnerability from the August Microsoft Patch Tuesday. The victim clicks on the attacker's link, memory corruption occurs and arbitrary attacker's code is executed.

The tricky part is that the victim has to open the link in Microsoft Edge browser in Internet Explorer compatibility mode. But why would the victim want to set the browser to this mode?

🔻 The victim may be using some old corporate web application that only works in Internet Explorer, so the browser is configured this way. Not such a rare situation. 😏

🔻An attacker may try to convince the victim to enable the setting "Allow sites to be reloaded in Internet Explorer mode (IE mode)" in Edge. 🤷‍♂️

One way or another, the vulnerability is exploited in the wild and there is already a (semi?🤔)public exploit for it. My colleagues at PT ESC shared today how they found and tested this exploit. 🔍

На русском