CVE-2020-9292Unquoted Search Path or Element in Fortinet Fortisiem Windows Agent

Severity
9.8CRITICALNVD
EPSS
0.5%
top 33.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 4
Latest updateMay 24

Description

An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5fortinet/fortinet_fortisiemwindowsagentFortiSIEMWindowsAgent 3.1.2

🔴Vulnerability Details

2
GHSA
GHSA-qm43-fv69-q9v2: An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt exe2022-05-24
CVEList
CVE-2020-9292: An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt exe2020-06-04

📋Vendor Advisories

1
Fortinet
An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated p...2020-06-04
CVE-2020-9292 — Unquoted Search Path or Element | cvebase