CVE-2018-9191: High severity fortinet forticlient ssl vpn vulnerability
Published May 30, 2019
·Updated
A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attackers to execute unauthorized code or commands via the named pipe responsible for Forticlient updates.
Affected Software
1 affected component
Fortinet FortiClient Windows<=6.0.4
Event History
May 30, 2019
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this FortiClient vulnerability?
The vulnerability ID for this FortiClient vulnerability is CVE-2018-9191.
2
What is the severity of CVE-2018-9191?
The severity of CVE-2018-9191 is high with a severity value of 7.8.
3
Which versions of Fortinet FortiClient for Windows are affected by CVE-2018-9191?
Fortinet FortiClient for Windows 6.0.4 and earlier versions are affected by CVE-2018-9191.
4
What can attackers do with CVE-2018-9191?
Attackers can execute unauthorized code or commands via the named pipe responsible for Forticlient updates with CVE-2018-9191.
5
Is there a solution for CVE-2018-9191?
Yes, Fortinet has released a patch to address CVE-2018-9191. It is recommended to update to the latest version of Fortinet FortiClient for Windows to mitigate the vulnerability.