PT-2021-23786 · Fortinet · Forticlient

Published

2021-12-09

·

Updated

2021-12-10

·

CVE-2021-43204

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Fortinet FortiClientWindows versions 6.4.1 through 6.4.0 Fortinet FortiClientWindows version 6.2.9 and earlier Fortinet FortiClientWindows version 6.0.10 and earlier
Description The issue is related to improper control of a resource through its lifetime, allowing an attacker to cause a complete denial of service of its components via changes of directory access permissions.
Recommendations For versions 6.4.1 and 6.4.0, update to a version that fixes the issue. For version 6.2.9 and earlier, update to a version that fixes the issue. For version 6.0.10 and earlier, update to a version that fixes the issue. As a temporary workaround, consider restricting access to the affected components to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-43204

Affected Products

Forticlient