cbcvebase.
CVE-2019-5589
published 2019-05-28

CVE-2019-5589: An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control…

PriorityP341high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
2.61%
83.6th percentile
An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in which FortiClientOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious .dll files in that directory.

Affected

8 ranges
VendorProductVersion rangeFixed in
fortinetforticlient< 6.0.66.0.6
fortinetforticlient
fortinetforticlientemergencymanagementserver
fortinetforticlientemsonlineinstaller
fortinetforticlientonlineinstaller
fortinetforticlientvirtualprivatenetwork
fortinetforticlientvpnonlineinstaller
fortinetfortinet_forticlient_for_windows

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.