Arbitrary XML file write in FCConfig
Summary
An Improper Link Resolution Before File Access vulnerability [CWE-59] in FortiClient Windows may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.
| Version | Affected | Solution |
|---|---|---|
| FortiClientWindows 8.0 | Not affected | Not Applicable |
| FortiClientWindows 7.4 | 7.4.0 through 7.4.4 | Upgrade to 7.4.5 or above |
| FortiClientWindows 7.2 | 7.2.0 through 7.2.12 | Upgrade to 7.2.13 or above |
| FortiClientWindows 7.0 | 7.0 all versions | Migrate to a fixed release |