QID 378398
Date Published: 2023-04-13
QID 378398: Fortinet FortiClient for Windows Arbitrary File Creation Vulnerability (FG-IR-22-320)
A relative path traversal vulnerability in FortiClient Windows may allow a local low privileged attacker to perform arbitrary file creation on the device filesystem.
Affected Versions:
FortiClientWindows version 7.0.0 through 7.0.7
FortiClientWindows 6.4 all versions
FortiClientWindows 6.2 all versions
FortiClientWindows 6.0 all versions
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.exe.
Successful exploitation of the vulnerability may allow an attacker to upload arbitrary files.
Solution
Users are advised to upgrade to the latest version FortiClient. Please refer FG-IR-22-320 for further information.
Vendor References
- FG-IR-22-320 -
www.fortiguard.com/psirt/FG-IR-22-320
CVEs related to QID 378398
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-320 |
|