QID 376653
Date Published: 2022-06-08
QID 376653: Forticlient Windows Privilege Escalation Vulnerability (FG-IR-21-238)
FortiClient is a comprehensive endpoint security solution.
An improper initialization vulnerability in FortiClient Windows may allow a local attacker to gain administrative privileges via placing a malicious executable inside the FortiClient installer's directory.
Affected Versions:
FortiClient (Windows) version 6.0.10 and below
FortiClient (Windows) version 6.2.9 and below
FortiClient (Windows) version 6.4.7 and below
FortiClient (Windows) version 7.0.2 and below
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.exe.
Vulnerability may allow attacker to gain administrative privileges
Solution
Users are advised to upgrade to the latest version FortiClient 6.4.8 or 7.0.3 of the software. Forticlient
Vendor References
- FG-IR-21-238 -
www.fortiguard.com/psirt/FG-IR-21-238
CVEs related to QID 376653
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-238 |
|