Online Installer DLL Hijacking
Summary
An untrusted search path vulnerability [CWE-426] in FortiClient Windows may allow an attacker to run arbitrary code via DLL hijacking and social engineering.
| Version | Affected | Solution |
|---|---|---|
| FortiClientWindows 7.4 | 7.4.0 | Upgrade to 7.4.1 or above |
| FortiClientWindows 7.2 | 7.2.0 through 7.2.4 | Upgrade to 7.2.5 or above |
| FortiClientWindows 7.0 | 7.0.0 through 7.0.12 | Upgrade to 7.0.13 or above |
Workaround
Ensure that all download executables are downloaded directly from Fortinet.
Acknowledgement
Fortinet is pleased to thank Aleksandar Marceta-Pavlovic from WKO Inhouse GmbH of the Austrian Economic Chambers for reporting this vulnerability under responsible disclosure.Timeline
2024-11-12: Initial publication2024-11-12: Adding workaround
2024-11-13: Fixed typos