PT-2021-23786 · Fortinet · Forticlient
Published
2021-12-09
·
Updated
2021-12-10
·
CVE-2021-43204
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiClientWindows versions 6.4.1 through 6.4.0
Fortinet FortiClientWindows version 6.2.9 and earlier
Fortinet FortiClientWindows version 6.0.10 and earlier
Description
The issue is related to improper control of a resource through its lifetime, allowing an attacker to cause a complete denial of service of its components via changes of directory access permissions.
Recommendations
For versions 6.4.1 and 6.4.0, update to a version that fixes the issue.
For version 6.2.9 and earlier, update to a version that fixes the issue.
For version 6.0.10 and earlier, update to a version that fixes the issue.
As a temporary workaround, consider restricting access to the affected components to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Forticlient