Unsafe Search Path Vulnerability in FortiClient by Fortinet
CVE-2021-32592
7.8HIGH
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 1 December 2021
What is CVE-2021-32592?
This vulnerability revolves around an unsafe search path in FortiClient and FortiClientEMS, affecting multiple versions. An attacker could exploit this flaw by placing a malicious OpenSSL engine library in the search path, facilitating a DLL Hijack attack on the affected devices. Such an attack could potentially compromise sensitive information and the integrity of the system. Organizations using the impacted versions should assess their risk and apply necessary mitigations to safeguard their infrastructure.
Affected Version(s)
Fortinet FortiClientWindows, FortiClientEMS FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x; FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x