Vulnerabilities > CVE-2018-9190 - NULL Pointer Dereference vulnerability in Fortinet Forticlient

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
fortinet
CWE-476
nessus

Summary

A null pointer dereference vulnerability in Fortinet FortiClientWindows 6.0.2 and earlier allows attacker to cause a denial of service via the NDIS miniport driver.

Common Weakness Enumeration (CWE)

Nessus

NASL familyWindows
NASL idFORTICLIENT_6_0_3.NASL
descriptionThe version of Fortinet FortiClient running on the remote host is prior to 6.0.3. It is, therefore, affected by a NULL pointer dereference flaw due to a failure to utilize necessary NULL checks before doing indirect function calls. An unauthenticated, local attacker can exploit this, via the NDIS Miniport drivers, to cause a denial of service condition when the application attempts to read or write memory with a NULL pointer.
last seen2020-06-01
modified2020-06-02
plugin id122858
published2019-03-14
reporterThis script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/122858
titleFortinet FortiClient NDIS Miniport Driver Null Pointer Dereference