Unsafe Search Path Vulnerability in FortiClient by Fortinet
CVE-2019-5589

7.8HIGH

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
28 May 2019

Summary

An Unsafe Search Path vulnerability exists in the FortiClient Online Installer for Windows versions prior to 6.0.6. This flaw could be exploited by an unauthenticated remote attacker who has control over the directory containing FortiClientOnlineInstaller.exe, enabling them to execute arbitrary code on the affected system. The attacker can achieve this by uploading malicious .dll files into the installer's directory, leading to potential system compromise.

Affected Version(s)

Fortinet FortiClient for Windows FortiClient for Windows version below 6.0.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.