Rewterz

Rewterz Threat Advisory – Multiple Fortinet FortiClientWindows Vulnerabilities

November 15, 2023

Severity

High

Analysis Summary

CVE-2023-38177 CVSS:6.1

Microsoft SharePoint Server could allow a remote authenticated attacker within the local network to execute arbitrary code on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the server.

CVE-2023-36021 CVSS:8

Microsoft On-Prem Data Gateway could allow a remote authenticated attacker to bypass security restrictions. An attacker could exploit this vulnerability to bypass security features to cause an impact on confidentiality, integrity and availability.

Impact

  • Security Bypass
  • Code Execution

Indicators Of Compromise

CVE

  • CVE-2023-38177
  • CVE-2023-36021

Affected Vendors

Microsoft

Affected Products

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition
  • Microsoft Host Integration Server 2020

Remediation

Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

CVE-2023-38177

CVE-2023-36021