Insecure Installation Folder
Summary
An incorrect default permissions [CWE-276] vulnerability in FortiClient (Windows) and FortiConverter (Windows) may allow a local authenticated attacker to tamper with files in the installation folder, if FortiClient or FortiConvreter is installed in an insecure folder.
Affected Products
FortiConverter version 7.0.0FortiConverter version 6.2.0 through 6.2.1
FortiConverter 6.0 all versions
FortiConverter 5.6 all versions are not affected
FortiClientWindows 7.2 all versions are not affected
FortiClientWindows version 7.0.0 through 7.0.6
FortiClientWindows version 6.4.0 through 6.4.8
FortiClientWindows 6.2 all versions are not affected
Solutions
Please upgrade to FortiClientWindows version 7.0.7 or above
Please upgrade to FortiClientWindows version 6.4.9 or above
Please upgrade to FortiConverter version 7.0.1 or above
Please upgrade to FortiConverter version 6.2.2 or above