CVE-2022-43946 HIGH

CVE-2022-43946

Vendor Fortinet
Product FortiClientWindows
Weakness CWE-732
Published April 11, 2023
Last update October 23, 2024

CVSS base score

7.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C

What the vulnerability does

01Description

Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file sharing network to execute commands via writing data into a windows pipe.

Key dates

02Disclosure timeline

April 11, 2023 CVE published
October 23, 2024 Record updated