PT-2021-3592 · Fortinet · Forticlient

Brsn

·

Published

2021-06-05

·

Updated

2022-03-30

·

CVE-2021-26089

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiClient for Mac versions 6.4.3 and below
Description The issue is related to an improper symlink following in FortiClient for Mac, which may allow a non-privileged user to execute arbitrary privileged shell commands during the installation phase. This could potentially enable an attacker to run arbitrary code.
Recommendations For FortiClient for Mac versions 6.4.3 and below, consider updating to a version above 6.4.3 to resolve the issue. As a temporary workaround, restrict access to the installation phase to minimize the risk of exploitation.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03696
CVE-2021-26089
ZDI-21-693
ZDI-22-078

Affected Products

Forticlient