CVE-2022-43946: Race Condition
Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file sharing network to execute commands via writing data into a windows pipe.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-43946?
CVE-2022-43946 is a vulnerability in Fortinet FortiClientWindows before version 7.0.7 that allows attackers on the same file sharing network to execute arbitrary code via a time-of-check time-of-use (TOCTOU) race condition.
What is the severity of CVE-2022-43946?
The severity of CVE-2022-43946 is rated as high with a CVSS score of 8.1.
How does CVE-2022-43946 affect Fortinet FortiClient?
CVE-2022-43946 affects Fortinet FortiClientWindows before version 7.0.7 by allowing attackers on the same file sharing network to execute arbitrary code.
How can I fix CVE-2022-43946?
To fix CVE-2022-43946, update Fortinet FortiClientWindows to version 7.0.7 or later.
Are there any references for CVE-2022-43946?
Yes, you can find more information about CVE-2022-43946 at the Fortinet FortiGuard Advisory website: https://fortiguard.com/psirt/FG-IR-22-429