PT-2022-3516 · Fortinet · Forticlient
Published
2022-07-05
·
Updated
2022-07-25
·
CVE-2021-41031
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiClient for Windows versions 7.0.2 and prior
FortiClient for Windows versions 6.4.6 and prior
FortiClient for Windows versions 6.2.9 and below
Description
A relative path traversal issue in the FortiESNAC service may allow a local unprivileged attacker to escalate their privileges to SYSTEM. The vulnerability is related to errors in directory path handling.
Recommendations
For FortiClient for Windows versions 7.0.2 and prior, update to a version later than 7.0.2 to resolve the issue.
For FortiClient for Windows versions 6.4.6 and prior, update to a version later than 6.4.6 to resolve the issue.
For FortiClient for Windows versions 6.2.9 and below, update to a version later than 6.2.9 to resolve the issue.
Fix
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Forticlient