CRITICAL🇵🇱 Wersja polska

CVE-2023-45590

CVSS 9.6v3.1pub. 2024-04-09upd. 2025-01-17

An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website

🤖 AI Analysis
How it works

The vulnerability results from improper code generation control (CWE-94) in the FortiClientLinux application. An attacker prepares a malicious website and then persuades a FortiClientLinux user to visit it. The interaction of the client application with the content of this website leads to the execution of untrusted code in the context of the FortiClientLinux process. The attack is possible remotely without requiring privileges on the attacker's side, with minimal user interaction.

Impact

An attacker can execute arbitrary code or commands on the victim's system, which may lead to complete host compromise, disclosure of sensitive data, and violation of system integrity and availability.

Mitigation & patch

FortiClientLinux should be updated to a version without the vulnerability in accordance with the manufacturer's recommendations published at https://fortiguard.com/psirt/FG-IR-23-087. Until the update is applied, internet browsing capabilities should be restricted for users running vulnerable client versions and they should be made aware of the risks of visiting unknown websites.

Who is affected

Fortinet FortiClientLinux in versions: 7.2.0, 7.0.6 to 7.0.10, and 7.0.3 to 7.0.4

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Fortinet Forticlient

    APP
    Fortinet
    7.0.37.0.47.2.07.0.6 – 7.0.11 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-17658CRITICAL9.8PL ✓same product

Unquoted service path w FortiClient Windows — privilege escalation

CVE-2026-24018HIGH7.8same product

A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, Forti...

CVE-2025-62676HIGH7.1same product

An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fort...

CVE-2025-47761HIGH7.8same product

An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClien...

CVE-2025-46373HIGH7.8same product

A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 throug...