Unsafe Search Path Vulnerability in FortiClient by Fortinet
CVE-2019-5589
7.8HIGH
Key Information:
- Vendor
- Fortinet
- Vendor
- CVE Published:
- 28 May 2019
Summary
An Unsafe Search Path vulnerability exists in the FortiClient Online Installer for Windows versions prior to 6.0.6. This flaw could be exploited by an unauthenticated remote attacker who has control over the directory containing FortiClientOnlineInstaller.exe, enabling them to execute arbitrary code on the affected system. The attacker can achieve this by uploading malicious .dll files into the installer's directory, leading to potential system compromise.
Affected Version(s)
Fortinet FortiClient for Windows FortiClient for Windows version below 6.0.6
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved