Information disclosure through debug features
Summary
An active debug code vulnerability [CWE-489] in FortiClientWindows may allow a local attacker to run the application step by step and retrieve the saved VPN user password
| Version | Affected | Solution |
|---|---|---|
| FortiClientWindows 7.4 | 7.4.0 through 7.4.3 | Upgrade to 7.4.4 or above |
| FortiClientWindows 7.2 | 7.2.0 through 7.2.10 | Upgrade to 7.2.11 or above |
| FortiClientWindows 7.0 | 7.0 all versions | Migrate to a fixed release |