CVE-2021-44169

Description

A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6.4.7 and below, version 7.0.3 and below allows attacker to gain administrative privileges via placing a malicious executable inside the FortiClient installers directory.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.149

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-36183,CVE-2021-44169 are affected in Forticlient 7.0.1-windowsWindows
Multiple Vulnerabilities are affected in Forticlient (x64) 6.0.10Windows
Multiple Vulnerabilities are affected in Forticlient (x64) 6.2.9Windows
Multiple Vulnerabilities are affected in Forticlient 6.0.10Windows
Multiple Vulnerabilities are affected in Forticlient 6.2.9Windows
Vulnerabilities CVE-2021-36183,CVE-2021-41028,CVE-2021-44169 are affected in Forticlient (x64) 7.0.1Windows
Vulnerabilities CVE-2021-36183,CVE-2021-41028,CVE-2021-44169 are affected in Forticlient 7.0.1Windows
Improper Initialization Vulnerability (CVE-2021-44169)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234