CVE-2023-37939
CVSS 3.1 Score 3.3 of 10 (low)
Details
Summary
CVE-2023-37939 is a vulnerability affecting multiple versions of FortiClient for Windows, Linux, and Mac. This issue, classified as CWE-200 (Uncontrolled Resource Consumption or Exposure), enables a local authenticated attacker to access the list of files or folders excluded from malware scanning, without requiring Administrative privileges. This exposure of sensitive information could potentially aid an attacker in bypassing security measures and launching further attacks. Organizations using the affected FortiClient versions are advised to apply the necessary patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Fortinet FortiClient
Affected Vendors
- Fortinet