Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Andrzej_PL
New Contributor II

FortiClientEMS v7.2.6 - CVE-2024-11236 Out of Bounds Write Vulnerability

Hi,

I'm testing the FortiClient EMS solution on a trial license. After updating to version 7.2.6, the system detected the PHP CVE-2024-11236 Out of Bounds Write Vulnerability. Is there a way to report this to have the vulnerable application version updated?

1 Solution
dingjerry_FTNT

Hi @Andrzej_PL ,

 

Thanks for reporting this vulnerability.

 

We have this Mantis 1089768 tracking this issue.  The fix will be included in FortiClient EMS 7.2.7 GA.

Regards,

Jerry

View solution in original post

7 REPLIES 7
sjoshi
Staff
Staff

Hi,

 

Please refer:-

https://www.fortiguard.com/encyclopedia/endpoint-vuln/82436

 

I do not see forticlient ems is affected

Let us know if this helps.
Salon Raj Joshi
Andrzej_PL
New Contributor II

ok but it is scan result on ems server - version 7.2.6 is windows platform

 

Zrzut ekranu 2024-11-28 150916.png

sjoshi

This Forticlient is install in the wins server where EMS server is setup?

Let us know if this helps.
Salon Raj Joshi
Andrzej_PL
New Contributor II

exactly

Andrzej_PL

so... any ideas?

dingjerry_FTNT

Hi @Andrzej_PL ,

 

Thanks for reporting this vulnerability.

 

We have this Mantis 1089768 tracking this issue.  The fix will be included in FortiClient EMS 7.2.7 GA.

Regards,

Jerry
Andrzej_PL

Hi,

unfortunately, the problem remains in the new client version 7.2.7 - the version of the php application with the given vulnerability is still used. php.exe must be in version 8.3.14, and it is in 8.3.13

 

Zrzut ekranu 2024-12-13 100626.pngZrzut ekranu 2024-12-13 095428.pngZrzut ekranu 2024-12-13 095344.png

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors