QID 377708
Date Published: 2022-11-02
QID 377708: Forticlient Windows Arbitrary File Write Vulnerability (FG-IR-22-044)
FortiClient is a comprehensive endpoint security solution.
An execution with unnecessary privileges vulnerability in FortiClient Windows may allow a local attacker to perform an arbitrary file write on the system.
Affected Versions:
FortiClient Windows version 6.0.0 through 6.0.10
FortiClient Windows version 6.2.0 through 6.2.9
FortiClient Windows version 6.4.0 through 6.4.7
FortiClient Windows version 7.0.0 through 7.0.3
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.exe.
Successful exploitation of this vulnerability may allow a local attacker to perform an arbitrary file write on the system.
Solution
Users are advised to upgrade to the latest version FortiClient 6.4.8 or 7.0.4 of the software. Please refer Forticlient Advisory for further information.
Vendor References
- FG-IR-22-044 -
www.fortiguard.com/psirt/FG-IR-22-044
CVEs related to QID 377708
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-044 |
|