CVE-2019-6692: High severity fortinet forticlient ssl vpn vulnerability
Published Oct 24, 2019
·Updated
A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code execution via forging that DLL.
Affected Software
1 affected component
Fortinet FortiClient Windows<=6.2.0
Event History
Oct 24, 2019
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this Fortinet FortiClient vulnerability?
The vulnerability ID of this Fortinet FortiClient vulnerability is CVE-2019-6692.
2
What is the affected software version for this vulnerability?
The affected software version for this vulnerability is Fortinet FortiClient for Windows 6.2.0 and below.
3
What can a privileged attacker do with this vulnerability?
A privileged attacker can perform arbitrary code execution via forging a malicious DLL.
4
How can I fix this vulnerability in Fortinet FortiClient for Windows?
To fix this vulnerability, update Fortinet FortiClient for Windows to a version higher than 6.2.0.
5
Is there any additional reference material available for this vulnerability?
Yes, you can refer to the FortiGuard Advisory FG-IR-19-148 available at the provided link.