Improper access control in FortiEDR CollectorWindows - CVE-2023-44248
Published: November 20, 2023
Vulnerability identifier: #VU83264
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-44248
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A local administrator can prevent the collector service to start in the next system reboot by tampering with some registry keys of the service.
Affected software
FortiEDR CollectorWindows
How to mitigate CVE-2023-44248
Install updates from vendor's website.
FortiEDR CollectorWindows - addressed in versions 5.0.3.1016, 5.2.0.4581