An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer installation folder.
| Software | From | Fixed in |
|---|---|---|
| fortinet / forticlient | 7.0.0 | 7.2.12 |
| fortinet / forticlient | 7.4.0 | 7.4.4 |