CVE-2021-44169: High severity fortinet forticlient ssl vpn vulnerability
A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6.4.7 and below, version 7.0.3 and below allows attacker to gain administrative privileges via placing a malicious executable inside the FortiClient installer's directory.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Fortinet FortiClient vulnerability?
The vulnerability ID for this Fortinet FortiClient vulnerability is CVE-2021-44169.
What is the severity of CVE-2021-44169?
The severity of CVE-2021-44169 is high with a CVSS score of 8.8.
Which versions of Fortinet FortiClient (Windows) are affected by this vulnerability?
Fortinet FortiClient (Windows) versions 6.0.10 and below, 6.2.9 and below, 6.4.7 and below, and 7.0.3 and below are affected by this vulnerability.
How can an attacker gain administrative privileges using this vulnerability?
An attacker can gain administrative privileges by placing a malicious executable inside the FortiClient installer's directory.
Is there a patch or fix available for CVE-2021-44169?
Yes, it is recommended to update Fortinet FortiClient to a version that is not affected by this vulnerability.