CVE-2023-41840: High severity Fortinet FortiClient Windows vulnerability
A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-41840.
What is the title of the vulnerability?
The title of the vulnerability is 'A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to per…'
What is the description of the vulnerability?
The vulnerability is a untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 that allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.
What software versions are affected by the vulnerability?
The vulnerability affects Fortinet FortiClient versions 7.0.9, 7.2.0, and 7.2.1 on Windows.
What is the severity of the vulnerability?
The severity of the vulnerability is high with a CVSS score of 7.4.
How can the vulnerability be fixed?
To fix the vulnerability, it is recommended to update Fortinet FortiClient to a version that is not affected by the issue.
Where can I find more information about the vulnerability?
You can find more information about the vulnerability on the Fortinet FortiGuard website: https://fortiguard.com/psirt/FG-IR-23-274
What is the CWE ID of the vulnerability?
The CWE ID of the vulnerability is 426.