FortiClient 7.4.3 VPN Voulnerability
Hi, our Scom team raised the following voulnearbility in 7.4.3. Support offers upgrade to PAID! version 7.4.4. and doesn’t offer any vulnerability mitigation process. Is that normal approach in Fortinet??
Summary: An Uncontrolled Search Path Element vulnerability (CWE-427) exists in FortiClient Windows versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, and all versions of 7.0. This vulnerability allows a local low-privileged user to execute a DLL hijacking attack by placing a malicious DLL in the FortiClient Online Installer installation folder. Impact: Exploitation of this vulnerability could enable unauthorized execution of malicious code, potentially compromising system integrity and security. Remediation: Upgrade to the latest version of Fortinet Forticlient.