CVE-2020-9292: Critical severity fortinet fortisiem vulnerability
Published Jun 4, 2020
·Updated
An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.
Affected Software
1 affected component
Fortinet Fortisiem Windows Agent<=3.1.2
Event History
Jun 4, 2020
CVE Published
via MITRE·12:41 PM
Data Sourced
via MITRE·12:41 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-9292?
CVE-2020-9292 has a medium severity rating, indicating a potential for exploitation that could lead to elevated privileges.
2
How do I fix CVE-2020-9292?
To fix CVE-2020-9292, ensure that the FortiSIEM Windows Agent is updated to version 3.1.3 or later.
3
What component is affected by CVE-2020-9292?
CVE-2020-9292 affects the FortiSIEM Windows Agent component specifically.
4
What exploitation method is associated with CVE-2020-9292?
CVE-2020-9292 is exploited via an unquoted service path in the AoWinAgt executable.
5
Can CVE-2020-9292 lead to remote attacks?
CVE-2020-9292 is capable of local privilege escalation but does not directly facilitate remote attacks.