CVE-2019-17658

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
12/03/2020
Last modified:
29/04/2021

Description

An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* 6.0.0 (including) 6.0.9 (including)
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* 6.2.0 (including) 6.2.2 (including)


References to Advisories, Solutions, and Tools