CVE-2020-9290
15.03.2020, 22:15
An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory.Enginsight
| Vendor | Product | Version |
|---|---|---|
| fortinet | forticlient | 𝑥 ≤ 6.2.3 |
| fortinet | forticlient_virtual_private_network | 𝑥 ≤ 6.2.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration