PT-2023-9673 · Fortinet · Forticlient

CVE-2022-43946

·

Publicado

2023-04-11

·

Atualizado

2024-04-11

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fortinet FortiClientWindows versions prior to 7.0.7
Description The issue is related to an incorrect permission assignment for a critical resource and a time-of-check time-of-use (TOCTOU) race condition vulnerability. This could allow a remote attacker to execute arbitrary commands by writing data into a Windows pipe. The vulnerability can be exploited by attackers on the same file sharing network.
Recommendations For versions prior to 7.0.7, update to version 7.0.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the Windows pipe to minimize the risk of exploitation. Avoid using the vulnerable function until a patch is available.

Correção

Incorrect Permission

Time Of Check To Time Of Use

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-09636
CVE-2022-43946
ZDI-23-1104

Produtos afetados

Forticlient