CVE-2024-36507
published 2024-11-12CVE-2024-36507: A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.28%
20.1th percentile
A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | — | — |
| fortinet | forticlient | >= 7.0.0 < 7.0.13 | 7.0.13 |
| fortinet | forticlient | >= 7.2.0 < 7.2.5 | 7.2.5 |
| fortinet | forticlientwindows | — | — |
| fortinet | forticlientwindows | — | — |
| fortinet | forticlientwindows | 7.0.0 – 7.0.12 | — |
| fortinet | forticlientwindows | 7.2.0 – 7.2.4 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 thr...
vendor_fortinet·2024-11-12·CVSS 7.3
CVE-2024-36507 [HIGH] CWE-426 A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 thr...
FG-IR-24-205: A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 thr...
A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.
CVEs: CVE-2024-36507
CWEs: CWE-426
CVSS: 7.3 (high)
Affected products: FortiClient, FortiClientWindows, Fortinet
GHSA
GHSA-rmph-8gw6-8rhx: A untrusted search path in Fortinet FortiClientWindows versions 7
ghsa_unreviewed·2024-11-12
CVE-2024-36507 [HIGH] CWE-426 GHSA-rmph-8gw6-8rhx: A untrusted search path in Fortinet FortiClientWindows versions 7
A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-12
Published