QID 378399
Date Published: 2023-04-13
QID 378399: Fortinet FortiClient for Windows Improper Write Access Vulnerability (FG-IR-22-429)
Multiple vulnerabilities including an incorrect permission assignment for critical resource vulnerability and a time-of-check time-of-use (TOCTOU) race condition vulnerability in FortiClient Windows may allow an attacker on the same file sharing network to execute commands via writing data into a windows pipe.
Affected Versions:
FortiClientWindows version 7.0.0 through 7.0.7
FortiClientWindows 6.4 all versions
FortiClientWindows 6.2 all versions
FortiClientWindows 6.0 all versions
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.exe.
Successful exploitation of the vulnerability may allow an attacker to execute commands via writing data into a windows pipe.
Solution
Users are advised to upgrade to the latest version FortiClient. Please refer FG-IR-22-429 for further information.
Vendor References
- FG-IR-22-429 -
www.fortiguard.com/psirt/FG-IR-22-429
CVEs related to QID 378399
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-429 |
|