Untrusted Search Path Vulnerability in Fortinet FortiClient Software
CVE-2023-41840

7.4HIGH

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
14 November 2023

Summary

A vulnerability exists in Fortinet FortiClient software, specifically in version 7.0.9, that allows an attacker to execute a DLL Hijack attack. This security flaw arises from an untrusted search path, which can be exploited through a malicious OpenSSL engine library. By leveraging this vulnerability, attackers can potentially execute harmful code on affected systems, compromising the integrity and confidentiality of sensitive data. It is crucial for users to stay informed about this issue and apply the necessary security updates to mitigate risks.

Affected Version(s)

FortiClientWindows 7.2.0 <= 7.2.1

FortiClientWindows 7.0.9

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.