FSSO stack-based buffer overflow
Prior to build 237, the Windows version of FSSO can be remotely exploited to run arbitrary code over the TCP/8000 port without being authenticated.
Remote code execution
Upgrade to FSSO build 237 or above.
32 bits and 64 bits respectively named FSSO_Setup_5.0.0237.exe and FSSO_Setup_5.0.0237_x64.exe are available in the / FortiGate/ v5.00/ 5.2/ 5.2.3/ FSSO/ directory from support download website.
FSSO build 237 is compatible with all FortiOS versions.
Thank you to Enrique Nissim from CoreSecurity exploit writing Team for responsibly disclosing this vulnerability to Fortinet.