Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
samrein
New Contributor

Issue on our FortClient EWS MSSQL$FCEMS

Hello together,

I received a notification from our Crowd Strike Endpoint solution.

Crowdstrike stops an unknown process:

msiexec /q /i c:\windows\temp\aq.msi

I cannot find the msi package at the temp folder. 
The local EventManager shows a entry: Configuration option 'show advanced options' changed from 0 to 1. Run the RECONFIGURE statement to install.


I think that the sql server service starts the installation from the msi package. 
Crowd and Microsoft Defender do not find any other threats.
The Fortigate is patched to version 7.0.14. EWS is on Build 7.07.
What further checks can I do to be sure to prevent a security lack?


Capture.PNG

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello samrein,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello samrein,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello samrein,

 

One of our expert is suggesting to raise a ticket to our TAC:

https://support.fortinet.com/welcome/#/

 

They will help you to resolve this.

 

Regards,

Anthony

 

Anthony-Fortinet Community Team.
Labels
Top Kudoed Authors