Improper access control in FortiEDR CollectorWindows - CVE-2023-44248

 

Improper access control in FortiEDR CollectorWindows - CVE-2023-44248

Published: November 20, 2023


Vulnerability identifier: #VU83264
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-44248
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A local administrator can prevent the collector service to start in the next system reboot by tampering with some registry keys of the service.


Affected software

FortiEDR CollectorWindows

How to mitigate CVE-2023-44248

Install updates from vendor's website.

FortiEDR CollectorWindows - addressed in versions 5.0.3.1016, 5.2.0.4581

External References

Related Security Bulletins