QID 379022
Date Published: 2023-11-23
QID 379022: Fortinet FortiClient for Windows Escalation of Privilege Vulnerability (FG-IR-23-274)
An untrusted search path vulnerability [CWE-426] in FortiClient Windows OpenSSL component may allow an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.
Affected Versions:
FortiClientWindows version 7.2.0 through 7.2.1
FortiClientWindows version 7.0.9
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.exe.
Successful exploitation of the vulnerability may allow an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.
Solution
Users are advised to upgrade to the latest version FortiClient. Please refer FG-IR-23-274 for further information.
Vendor References
- FG-IR-23-274 -
www.fortiguard.com/psirt/FG-IR-23-274
CVEs related to QID 379022
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-274 |
|