PT-2019-17767 · Fortinet · Forticlient Online Installer
Published
2019-05-28
·
Updated
2019-05-29
·
CVE-2019-5589
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiClient Online Installer versions prior to 6.0.6
Description
The issue allows an unauthenticated, remote attacker with control over the directory where FortiClientOnlineInstaller.exe is located to execute arbitrary code on the system. This is achieved by uploading malicious .dll files to that directory.
Recommendations
For versions prior to 6.0.6, update to version 6.0.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the directory where FortiClientOnlineInstaller.exe resides to prevent malicious .dll files from being uploaded.
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forticlient Online Installer