Protection may be disabled by local attacker

Summary

An improper access control vulnerabilty [CWE-284] in FortiEDRCollectorWindows may allow a local attacker to prevent the collector service to start in the next system reboot by tampering with some registry keys of the service.

Affected Products

FortiEDR CollectorWindows 5.2 all versions are not affected
FortiEDR CollectorWindows 5.1 all versions are not affected
FortiEDR CollectorWindows version 5.0.0 through 5.0.2

Solutions

Please upgrade to FortiEDRCollectorWindows version 5.2.0.4581 or above
Please upgrade to FortiEDRCollectorWindows version 5.0.3.1016 or above

Timeline

2023-11-07: Initial publication