PT-2023-7194 · Fortinet · Forticlient
CVE-2023-41840
·
Publicado
2023-11-14
·
Atualizado
2023-11-21
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiClientWindows version 7.0.9
Description
The issue is related to an untrusted search path vulnerability that allows an attacker to perform a DLL Hijack attack. This can be achieved by placing a malicious OpenSSL engine library in the search path, which can lead to arbitrary code execution. The vulnerability is associated with the exploitation of a legitimate DLL file being replaced by a malicious library.
Recommendations
For Fortinet FortiClientWindows version 7.0.9, consider restricting access to the search path to prevent malicious libraries from being loaded, until a patch is available. As a temporary workaround, avoid using the vulnerable OpenSSL engine library in the affected search path.
Correção
Untrusted Search Path
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Forticlient