CVE-2023-44248
FortiEDR vulnerability analysis and mitigation

Overview

An improper access control vulnerability (CVE-2023-44248) was discovered in FortiEDRCollectorWindows. The vulnerability was disclosed on November 14, 2023, affecting FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, and all versions of 4.0. This vulnerability has been assigned a medium severity rating with a CVSS v3.1 score of 4.4 (Fortinet Advisory, NVD).

Technical details

The vulnerability is classified as an improper access control issue (CWE-284). It allows a local attacker with privileges to tamper with specific registry keys of the service, which can prevent the collector service from starting during the next system reboot. The CVSS v3.1 metrics indicate a Local attack vector (AV:L), Low attack complexity (AC:L), High privileges required (PR:H), and No user interaction needed (UI:N) (NVD).

Impact

The primary impact of this vulnerability is a denial of service condition, specifically preventing the FortiEDR collector service from starting after a system reboot. This affects the availability of the service while having no direct impact on confidentiality or integrity of the system (Fortinet Advisory).

Mitigation and workarounds

Fortinet has released patches to address this vulnerability. Users are advised to upgrade to FortiEDRCollectorWindows version 5.2.0.4581 or above, or version 5.0.3.1016 or above, depending on their current version (Fortinet Advisory).

Additional resources


SourceThis report was generated using AI

Related FortiEDR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-33303HIGH8.1
  • FortiEDRFortiEDR
  • cpe:2.3:a:fortinet:fortiedr
NoYesOct 13, 2023
CVE-2022-23440HIGH7.8
  • FortiEDRFortiEDR
  • cpe:2.3:a:fortinet:fortiedr
NoYesApr 06, 2022
CVE-2023-44248MEDIUM5.5
  • FortiEDRFortiEDR
  • cpe:2.3:a:fortinet:fortiedr
NoYesNov 14, 2023
CVE-2022-39949MEDIUM5.5
  • FortiEDRFortiEDR
  • cpe:2.3:a:fortinet:fortiedr
NoYesNov 02, 2022
CVE-2022-29057MEDIUM5.4
  • FortiEDRFortiEDR
  • cpe:2.3:a:fortinet:fortiedr
NoYesJul 19, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management