A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.
History

Thu, 14 Nov 2024 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet forticlient
CPEs cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*
cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:windows:*:*
Vendors & Products Fortinet forticlient

Tue, 12 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet
Fortinet forticlientwindows
CPEs cpe:2.3:a:fortinet:forticlientwindows:*:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet forticlientwindows
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 19:00:00 +0000

Type Values Removed Values Added
Description A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2024-11-12T18:53:46.362Z

Updated: 2024-11-12T21:29:44.901Z

Reserved: 2024-05-29T08:44:50.759Z

Link: CVE-2024-36507

cve-icon Vulnrichment

Updated: 2024-11-12T21:29:38.061Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-12T19:15:10.233

Modified: 2024-11-14T20:31:45.367

Link: CVE-2024-36507

cve-icon Redhat

No data.