QID 378405
QID 378405: FortiClient Mac Privilege Escalation Vulnerability (FG-IR-22-481)
FortiClient is a comprehensive endpoint security solution. FortiOS allows organizations to control the security and networking capabilities with one intuitive operating system.
CVE-2018-9195: Man-In-The-Middle Attack.
Affected Versions:
FortiClientMac version 7.0.0 through 7.0.7
FortiClientMac version 6.4 all versions
FortiClientMac version 6.2 all versions
FortiClientMac version 6.0 all versions
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.
Successful exploitation of the vulnerability may allow a local attacker to escalate their privileges via modifying the installer upon upgrade
Solution
Vendor has released fix to address these vulnerabilities. Refer to FG-IR-22-481
Vendor References
- FG-IR-22-481 -
www.fortiguard.com/psirt/FG-IR-22-481
CVEs related to QID 378405
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-481 |
|