PT-2021-3592 · Fortinet · Forticlient
Brsn
·
Published
2021-06-05
·
Updated
2022-03-30
·
CVE-2021-26089
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiClient for Mac versions 6.4.3 and below
Description
The issue is related to an improper symlink following in FortiClient for Mac, which may allow a non-privileged user to execute arbitrary privileged shell commands during the installation phase. This could potentially enable an attacker to run arbitrary code.
Recommendations
For FortiClient for Mac versions 6.4.3 and below, consider updating to a version above 6.4.3 to resolve the issue. As a temporary workaround, restrict access to the installation phase to minimize the risk of exploitation.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Forticlient