CVE-2023-45588: High severity fortinet forticlient vulnerability
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45588?
CVE-2023-45588 is considered a high-severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2023-45588?
To fix CVE-2023-45588, upgrade FortiClientMac to version 7.2.4 or later, or 7.0.11 or later.
Who is affected by CVE-2023-45588?
CVE-2023-45588 affects users of FortiClientMac versions 7.2.3 and below, as well as 7.0.10 and below.
What kind of vulnerability is CVE-2023-45588?
CVE-2023-45588 is an external control of file name or path vulnerability, classified under CWE-73.
Can CVE-2023-45588 be exploited remotely?
CVE-2023-45588 requires local access for exploitation, as it involves manipulating configuration files before installation.