QID 378397
Date Published: 2023-04-13
QID 378397: Fortinet FortiClient for Windows Arbitrary File Creation Vulnerability (FG-IR-22-336)
An incorrect authorization vulnerability in FortiClient (Windows) may allow a local low privileged attacker to perform arbitrary file creation in the device filesystem.
Affected Versions:
FortiClientWindows version 7.0.0 through 7.0.7
FortiClientWindows version 6.4.0 through 6.4.9
FortiClientWindows version 6.2.0 through 6.2.9
FortiClientWindows version 6.0.0 through 6.0.10
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.exe.
Successful exploitation of the vulnerability may allow an attacker to upload arbitrary files.
Solution
Users are advised to upgrade to the latest version FortiClient. Please refer FG-IR-22-336 for further information.
Vendor References
- FG-IR-22-336 -
www.fortiguard.com/psirt/FG-IR-22-336
CVEs related to QID 378397
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-336 |
|