Security Advisory

CVE-2020-9290

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-03-15 21:52:05
Last updated 2024-10-25 14:26:32
Assigner fortinet
State PUBLISHED

Description

An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory.