QID 378764
QID 378764: Fortinet FortiClient for Windows Incorrect Default Permissions Vulnerability (FG-IR-22-229)
An incorrect default permissions [CWE-276] vulnerability in FortiClient (Windows) may allow a local authenticated attacker to tamper with files in the installation folder, if FortiClient is installed in an insecure folder.
Affected Versions:
FortiClientWindows version 7.0.0 through 7.0.6
FortiClientWindows version 6.4.0 through 6.4.8
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.exe.
Successful exploitation of the vulnerability may allow an attacker to tamper with files in the installation folder.
Solution
Users are advised to upgrade to the latest version FortiClient. Please refer FG-IR-22-229 for further information.
Vendor References
- FG-IR-22-229 -
www.fortiguard.com/psirt/FG-IR-22-229
CVEs related to QID 378764
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-229 |
|