PT-2020-9939 · Fortinet · Fortitray+2
Published
2020-03-12
·
Updated
2021-04-29
·
CVE-2019-17658
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiClientWindows versions 6.2.2 and prior
Description
The issue is related to an unquoted service path vulnerability in the FortiTray component, allowing an attacker to gain elevated privileges via the FortiClientConsole executable service path.
Recommendations
For FortiClientWindows versions 6.2.2 and prior, update to a version that contains a fix for this issue to prevent exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forticlient
Forticlientconsole
Fortitray