Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools
Malicious actors are using a now-patched serious security issue that affects Fortinet FortiClient EMS as part of a cyber campaign that installs remote desktop programs like AnyDesk and ScreenConnect.
The SQL injection vulnerability in question is CVE-2023-48788 (CVSS score: 9.3), which enables attackers to submit specially constructed data packets and execute unauthorized code or commands.
The October 2024 attack, according to Russian cybersecurity firm Kaspersky, targeted a Windows server belonging to an unidentified corporation that was open to the internet and had two open ports connected to FortiClient EMS.
According to a Thursday investigation, the targeted organization uses this technology to enable staff members read more about Hackers Exploiting Critical Fortinet EMS Vuln...

