cbcvebase.
CVE-2019-17658
published 2020-03-12

CVE-2019-17658: An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated…

PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.18%
80.2th percentile
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.

Affected

7 ranges
VendorProductVersion rangeFixed in
fortinetforticlient
fortinetforticlient6.0.0 – 6.0.9
fortinetforticlient6.2.0 – 6.2.2
fortinetforticlientconsole
fortinetforticlientwindows
fortinetfortinet_forticlientwindows
fortinetfortitray

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.