7.5
CVSSv2

CVE-2019-17658

Published: 12/03/2020 Updated: 29/04/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an malicious user to gain elevated privileges via the FortiClientConsole executable service path.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet forticlient

Github Repositories

Unquoted Service Path exploit in FortiClient (CVE-2019-17658)

Unquoted Service Path exploit in FortiClient (CVE-2019-17658) FortiClient for Windows prior to 623 is vulnerable to an unquoted service path vulnerability That may allow an attacker to gain elevated privileges via the FortiClientConsole executable service path Base Score: 98 Vector: CVSS:31/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Component FortiClient FortiTray Affec