Denial of service due to folder access permission change
Summary
An improper control of a resource through its lifetime [CWE-664] vulnerability in FortiEDR Collector may allow a privileged attacker to make the application unresponsive via changing its root directory access permission.
Affected Products
FortiEDR Collector version 5.0.3 b0233 and earlier
Solutions
Upgrade to FortiEDR Collector version 5.0.3 b0508 or above
Acknowledgement
Fortinet is pleased to thank Mike de Almeida for reporting this vulnerability under responsible disclosureTimeline
2022-04-05: Initial publication