An Improper Control of Generation of Code (Code Injection) vulnerability — CWE-94 — in FortiClientLinux may allow an unauthenticated attacker to execute arbitrary code by tricking a FortiClientLinux user into visiting a malicious website.
CVE-2023-45590 details
- Severity: Critical — CVSS 9.4/10
- Exploitation status: No evidence of exploitation in the wild at time of publication
- CVE ID: CVE-2023-45590
Impact
Exploitation could allow execution of unauthorized code or commands, and potentially allow an unauthenticated attacker to execute arbitrary code by tricking a FortiClientLinux user into visiting a malicious website.
Affected products & remediation
| Version | Affected | Remediation |
|---|---|---|
| FortiClientLinux 7.2 | 7.2.0 | Upgrade to 7.2.1 or above |
| FortiClientLinux 7.0 | 7.0.3 through 7.0.4 · 7.0.6 through 7.0.10 | Upgrade to 7.0.11 or above |
References
What Digital Hands is doing
Without signs of exploitation and absent published Tactics, Techniques, and Procedures (TTPs) and Indicators of Compromise (IOCs), Digital Hands continues to monitor for new developments related to CVE-2023-45590. We'll update this bulletin as the situation evolves. Talk to a Cyber Expert if you'd like Digital Hands to monitor your environment.