NachoVPN Tool Exploits Flaws in Popular VPN Clients for System Compromise

Teilen:

Cybersecurity researchers have disclosed a set of flaws impacting Palo Alto Networks and SonicWall virtual private network (VPN) clients that could be potentially exploited to gain remote code execution on Windows and macOS systems.

“By targeting the implicit trust VPN clients place in servers, attackers can manipulate client behaviours, execute arbitrary commands, and gain high levels of access with minimal effort,” AmberWolf said in an analysis.

In a hypothetical attack scenario, this plays out in the form of a rogue VPN server that can trick the clients into downloading malicious updates that can cause unintended consequences.

The result of the investigation is a proof-of-concept (PoC) attack tool called NachoVPN that can simulate such VPN servers and exploit the vulnerabilities to achieve privileged code execution.

The identified flaws are listed below –

  • CVE-2024-5921 (CVSS score: 5.6) – An insufficient certificate validation vulnerability impacting Palo Alto Networks GlobalProtect for Windows, macOS, and Linux that allows the app to be connected to arbitrary servers, leading to the deployment of malicious software (Addressed in version 6.2.6 for Windows)
  • CVE-2024-29014 (CVSS score: 7.1) – A vulnerability impacting SonicWall SMA100 NetExtender Windows client that could allow an attacker to execute arbitrary code when processing an End Point Control (EPC) Client update. (Affects versions 10.2.339 and earlier, addressed in version 10.2.341)

Palo Alto Networks has emphasized that the attacker needs to either have access as a local non-administrative operating system user or be on the same subnet so as to install malicious root certificates on the endpoint and install malicious software signed by the malicious root certificates on that endpoint.

In doing so, the GlobalProtect app could be weaponized to steal a victim’s VPN credentials, execute arbitrary code with elevated privileges, and install malicious root certificates that could be used to facilitate other attacks.

Similarly, an attacker could trick a user to connect their NetExtender client to a malicious VPN server and then deliver a counterfeit EPC Client update that’s signed with a valid-but-stolen certificate to ultimately execute code with SYSTEM privileges.

“Attackers can exploit a custom URI handler to force the NetExtender client to connect to their server,” AmberWolf said. “Users only need to visit a malicious website and accept a browser prompt, or open a malicious document for the attack to succeed.”

While there is no evidence that these shortcomings have been exploited in the wild, users of Palo Alto Networks GlobalProtect and SonicWall NetExtender are advised to apply the latest patches to safeguard against potential threats.

The development comes as researchers from Bishop Fox detailed its approach to decrypting and analyzing the firmware embedded in SonicWall firewalls to further aid in vulnerability research and build fingerprinting capabilities in order to assess the current state of SonicWall firewall security based on internet-facing exposures.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:47 am, Juni 15, 2025
Wetter-Symbol 18°C
L: 17° | H: 20°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 71 %
Druck: 1022 mb
Wind: 10 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 40%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:42 am
Sonnenuntergang: 9:19 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 20°°C 0 mm 0% 12 mph 74 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 25°°C 0 mm 0% 9 mph 85 % 1028 mb 0 mm/h
Di. Juni 17 10:00 pm
Wetter-Symbol
16° | 26°°C 0 mm 0% 10 mph 83 % 1027 mb 0 mm/h
Mi. Juni 18 10:00 pm
Wetter-Symbol
15° | 27°°C 0 mm 0% 7 mph 76 % 1026 mb 0 mm/h
Do. Juni 19 10:00 pm
Wetter-Symbol
17° | 28°°C 0 mm 0% 10 mph 76 % 1027 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
18° | 19°°C 0 mm 0% 9 mph 71 % 1022 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 22°°C 0 mm 0% 9 mph 65 % 1022 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
22° | 24°°C 0 mm 0% 11 mph 49 % 1022 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 12 mph 54 % 1023 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 8 mph 74 % 1025 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 5 mph 84 % 1027 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 3 mph 85 % 1027 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 3 mph 76 % 1028 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,140.71
0.19%
Ethereum(ETH)
€2,184.50
-0.45%
Fesseln(USDT)
€0.87
-0.01%
XRP(XRP)
€1.86
-1.20%
Solana(SOL)
€125.92
-0.20%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.151478
-1.09%
Shiba Inu(SHIB)
€0.000010
-1.19%
Pepe(PEPE)
€0.000010
-0.38%
Nach oben scrollen