1 min read
Multiple Vulnerabilities in Fortinet Products Could Allow for Arbitrary Code Execution
Published 03/14/2023 I. Targeted Entities Fortinet product users II. Introduction Multiple vulnerabilities have recently been identified in...
8 min read
Cyber Florida SOCAP Team
:
Updated on August 14, 2026
Published 04/13/2023
Several critical vulnerabilities were discovered in both Microsoft and Fortinet products, allowing remote and arbitrary code execution.
For both companies, these vulnerabilities can allow an attacker to install programs; view, change, or delete data; or create new accounts with full user rights. User accounts configured with fewer user rights could be less affected than those operating with administrative rights.
Microsoft has revealed that its April security update included fixes for 97 flaws, one of which was an actively exploited zero-day vulnerability. Microsoft reported seven vulnerabilities as “critical,” the most serious classification available. The types of vulnerabilities described in Microsoft’s advisory are as follows: privilege escalation, security feature bypass, remote code execution, information disclosure, denial of service, and spoofing (Abrams, 2023).
As for the zero-day vulnerability, known as CVE-2023-28252, it is a Windows common log file system driver elevation-of-privileges vulnerability that allows user privileges to be escalated to SYSTEM, the highest privilege in Windows. Microsoft also reported that this vulnerability was observed in the wild before the security updates patched it (MS-ISAC, 2023).
Moreover, a cybersecurity solutions provider, Fortinet, has announced a patch for several high-severity flaws in products such as FortiOS, FortiProxy, FortiSandbox, FortiWeb, FortiClient, and FortiManager. These issues could allow for cross-site scripting attacks, unauthorized API calls, command execution, arbitrary code execution, privilege escalation, and man-in-the-middle attacks. Fortinet also reported a critical missing-authentication vulnerability, tracked as CVE-2022-41331, with a CVSS score of 9.3, in the FortiPresence infrastructure server. This could be exploited by a remote, unauthenticated attacker via crafted authentication requests to access Redis and MongoDB instances (Arghire, 2023).
Affected Microsoft Systems:
Affected Fortinet Systems:
Microsoft Systems:
Apply Microsoft-provided patches or mitigations to vulnerable systems immediately after testing. (M1051: Update Software)
Fortinet Systems:
Apply appropriate updates provided by FortiNet to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
Arghire, I. (2023, April 12). Fortinet Patches Critical Vulnerability in Data Analytics Solution. SecurityWeek. Retrieved April 12, 2023, from https://www.securityweek.com/fortinet-patches-critical-vulnerability-in-data-analytics-solution/
Abrams, L. (2023, April 11). Microsoft April 2023 Patch Tuesday Fixes 1 Zero-day, 97 Flaws. BleepingComputer. Retrieved April 12, 2023, from https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2023-patch-tuesday-fixes-1-zero-day-97-flaws/
MS-ISAC. (2023, April 11). MS-ISAC CYBERSECURITY ADVISORY – Critical Patches Issued for Microsoft Products April 11, 2023 – PATCH NOW – TLP: CLEAR
MS-ISAC. (2023, April 12). MS-ISAC CYBERSECURITY ADVISORY – Multiple Vulnerabilities in Fortinet Products Could Allow for Arbitrary Code Execution – PATCH NOW – TLP: CLEAR
Security Analysts: Sreten Dedic
1 min read
Published 03/14/2023 I. Targeted Entities Fortinet product users II. Introduction Multiple vulnerabilities have recently been identified in...
1 min read
Originally Published March 4, 2025
1 min read
Originally published: 02/11/2025 I. Targeted Entities Organizations, researchers, and developers are leveraging Meta's Llama-Stack for AI model...