CVE-2021-43066
published 2022-05-11CVE-2021-43066: A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.9th percentile
A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version 6.0.10 and below allows attacker to escalate privilege via the MSI installer.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | >= 6.0.0 < 6.4.7 | 6.4.7 |
| fortinet | forticlient | >= 7.0.0 < 7.0.3 | 7.0.3 |
| fortinet | forticlientwindows | — | — |
| fortinet | fortinet | — | — |
| fortinet | fortinet_forticlientwindows | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below,...
vendor_fortinet·2022-05-11·CVSS 8.4
CVE-2021-43066 [HIGH] CWE-668 A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below,...
FG-IR-21-154: A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below,...
A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version 6.0.10 and below allows attacker to escalate privilege via the MSI installer.
CVEs: CVE-2021-43066
CWEs: CWE-668
CVSS: 8.4 (high)
Affected products: FortiClient, FortiClientWindows, Fortinet
GHSA
GHSA-726x-mfp5-rvmh: A external control of file name or path in Fortinet FortiClientWindows version 7
ghsa_unreviewed·2022-05-12
CVE-2021-43066 [HIGH] CWE-610 GHSA-726x-mfp5-rvmh: A external control of file name or path in Fortinet FortiClientWindows version 7
A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version 6.0.10 and below allows attacker to escalate privilege via the MSI installer.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-11
Published