PT-2019-17767 · Fortinet · Forticlient Online Installer
Publicado
2019-05-28
·
Atualizado
2019-05-29
·
CVE-2019-5589
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiClient Online Installer versions prior to 6.0.6
Description
The issue allows an unauthenticated, remote attacker with control over the directory where FortiClientOnlineInstaller.exe is located to execute arbitrary code on the system. This is achieved by uploading malicious .dll files to that directory.
Recommendations
For versions prior to 6.0.6, update to version 6.0.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the directory where FortiClientOnlineInstaller.exe resides to prevent malicious .dll files from being uploaded.
Correção
Untrusted Search Path
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Forticlient Online Installer