PT-2023-9673 · Fortinet · Forticlient
CVE-2022-43946
·
Publicado
2023-04-11
·
Atualizado
2024-04-11
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiClientWindows versions prior to 7.0.7
Description
The issue is related to an incorrect permission assignment for a critical resource and a time-of-check time-of-use (TOCTOU) race condition vulnerability. This could allow a remote attacker to execute arbitrary commands by writing data into a Windows pipe. The vulnerability can be exploited by attackers on the same file sharing network.
Recommendations
For versions prior to 7.0.7, update to version 7.0.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the Windows pipe to minimize the risk of exploitation. Avoid using the vulnerable function until a patch is available.
Correção
Incorrect Permission
Time Of Check To Time Of Use
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Forticlient