High severity7.8NVD Advisory· Published May 28, 2019· Updated Jun 17, 2026
CVE-2019-5589
CVE-2019-5589
Description
An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in which FortiClientOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious .dll files in that directory.
Affected products
3cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*+ 1 more
- cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*range: <6.0.6
- (no CPE)range: FortiClient for Windows version below 6.0.6
- Range: <6.0.6
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-19-060nvdVendor Advisory
News mentions
0No linked articles in our index yet.