CVE-2019-17658: Fortinet FortiClient

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.

Affected products

  • Fortinet FortiClient: from 6.0.0, up to and including 6.0.9; from 6.2.0, up to and including 6.2.2

Published 2020-03-12. Last modified 2026-06-17.