cbcvebase.
CVE-2020-9290
published 2020-03-15

CVE-2020-9290: An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in…

PriorityP433high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.60%
44.8th percentile
An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory.

Affected

9 ranges
VendorProductVersion rangeFixed in
fortinetforticlient<= 6.2.3
fortinetforticlient
fortinetforticlient_virtual_private_network<= 6.2.3
fortinetforticlientemergencymanagementserver
fortinetforticlientemsonlineinstaller
fortinetforticlientonlineinstaller
fortinetforticlientvirtualprivatenetwork
fortinetforticlientvpnonlineinstaller
fortinetfortinet_forticlient_for_windows

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.