#VU22808 OS Command Injection in Fortinet FortiClient for Windows - CVE-2019-15711
Published: November 18, 2019
Fortinet FortiClient for Windows
Fortinet, Inc
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation. A remote authenticated attacker can execute arbitrary OS commands through IPC socket by export logs on the system with running FortiClient for Linux.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.