cbcvebase.
CVE-2021-32592
published 2021-12-01

CVE-2021-32592: An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL engine library in the search path.

Affected

12 ranges
VendorProductVersion rangeFixed in
fortinetforticlient
fortinetforticlient
fortinetforticlient6.0.0 – 6.0.9
fortinetforticlient6.2.0 – 6.2.9
fortinetforticlient>= 6.4.0 < 6.4.76.4.7
fortinetforticlient_enterprise_management_server
fortinetforticlient_enterprise_management_server6.0.0 – 6.0.6
fortinetforticlient_enterprise_management_server6.2.0 – 6.2.9
fortinetforticlient_enterprise_management_server>= 6.4.0 < 6.4.76.4.7
fortinetforticlientems
fortinetforticliententerprisemanagementserver
fortinetforticlientwindows