An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL engine library in the search path.
| Software | From | Fixed in |
|---|---|---|
| fortinet / forticlient | 6.0.0 | 6.0.9.x |
| fortinet / forticlient_enterprise_management_server | 6.2.0 | 6.2.9.x |
| fortinet / forticlient | 6.4.0 | 6.4.7 |
| fortinet / forticlient | 7.0.0 | 7.0.0.x |
| fortinet / forticlient_enterprise_management_server | 6.0.0 | 6.0.6.x |
| fortinet / forticlient_enterprise_management_server | 6.4.0 | 6.4.7 |
| fortinet / forticlient_enterprise_management_server | 7.0.0 | 7.0.0.x |
| fortinet / forticlient | 6.2.0 | 6.2.9.x |