Arbitrary file creation by unprivileged users
Summary
A relative path traversal [CWE-23] vulnerability in FortiClientWindows may allow a local low privileged attacker to perform arbitrary file creation on the device filesystem.
| Version | Affected | Solution |
|---|---|---|
| FortiClientWindows 7.2 | Not affected | Not Applicable |
| FortiClientWindows 7.0 | 7.0.0 through 7.0.7 | Upgrade to 7.0.8 or above |
| FortiClientWindows 6.4 | 6.4 all versions | Migrate to a fixed release |
| FortiClientWindows 6.2 | 6.2 all versions | Migrate to a fixed release |
| FortiClientWindows 6.0 | 6.0 all versions | Migrate to a fixed release |
Acknowledgement
Fortinet is pleased to thank Daniel Hulliger from Armasuisse CYD Campus for reporting this vulnerability under responsible disclosure.
Timeline
2023-04-11: Initial publication