PoC Index

CVE-2019-17658

CRITICAL 9.8EPSS 2.2%

An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
2.18% chance of exploitation in the next 30 days, 81th percentile
Published
2020-03-12
Updated
2024-10-25

Proof-of-concept exploits (1)

References

Related