CVE-2019-17658
published 2020-03-12CVE-2019-17658: An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.18%
80.2th percentile
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | 6.0.0 – 6.0.9 | — |
| fortinet | forticlient | 6.2.0 – 6.2.2 | — |
| fortinet | forticlientconsole | — | — |
| fortinet | forticlientwindows | — | — |
| fortinet | fortinet_forticlientwindows | — | — |
| fortinet | fortitray | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior all...
vendor_fortinet·2020-03-12·CVSS 9.8
CVE-2019-17658 [CRITICAL] CWE-428 An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior all...
FG-IR-19-281: An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior all...
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.
CVEs: CVE-2019-17658
CWEs: CWE-428
CVSS: 9.8 (critical)
Affected products: FortiClient, FortiClientConsole, FortiClientWindows, FortiTray
GHSA
GHSA-m95v-g4pm-pcq9: An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6
ghsa_unreviewed·2022-05-24
CVE-2019-17658 [CRITICAL] CWE-428 GHSA-m95v-g4pm-pcq9: An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-03-12
Published