Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4gcf-xhrj-g4gq

Опубликовано: 14 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer installation folder.

An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer installation folder.

EPSS

Процентиль: 4%
0.00018
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 6.7
nvd
4 месяца назад

An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer installation folder.

EPSS

Процентиль: 4%
0.00018
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-427