B&B Bezpieczeństwo w biznesie
  • Start
  • O nas
  • Produkty
  • Usługi
    • Szkolenia
    • Cyberbezpieczny Samorząd
    • Audyt bezpieczeństwa informacji
      • Testy penetracyjne
      • Testy ataków socjotechnicznych
    • Audyt konfiguracji Fortigate
    • Prezentacje
    • Wdrożenia
  • Blog techniczny
  • Pomoc
  • Kariera
  • Kontakt

Producent oprogramowania FortiNet opublikował aktualizację dla produktu FortiClient 7.2.2 dla systemu Windows. Update zawiera wiele poprawek, które dotyczą zasad połączenia ZTNA, filtra sieciowego czy też samego interfejsu graficznego. Ponadto Forti Client dla Windows nie jest narażony na ujawnienie informacji w dzienniku agenta.

Rozwiązane problemy:

ZTNA connection rules

Bug ID Description
875254 FortiClient (Windows) cannot finish ZTNA TCP forwarding TFA authentication when FortiClient (Windows) disables Use external browser…
883269 FortiClient (Windows) stops logging service portal activities even though new TCP forwarding entries are configured on FortiOS.
914111 ZTNA daemon fortitcs stops updating its log file after running for some time.
918501 Zero trust network access (ZTNA) TCP forwarding (remote desktop protocol) does not work if encryption is enabled and LDAP authentication is used.
919540 ZTNA password can be seen in plain text format in GUI logs with basic authentication enabled.
933690 FortiClient (Windows) does not update Fortitcs logs after a few portal queries or forwarding connection.

Web Filter and plugin

Bug ID Description
867483 Web Filter does not give warning message.
915287 Extension does not properly apply safe mode HTTP header restrictions.
919419 Web Filter with FortiGuard Anycast spamming blocks (Unknown) alerts in Notifications.

GUI

Bug ID Description
913777 Action for cookies should be moved from Advanced > VPN to Settings.
926401 GUI error log should be in info log Failed to load REG_SSLVPN_SERVICE_PORT.
943787 Message keeps popping up on endpoint after user acknowledges it.

Endpoint control

Bug ID Description
900189 Connection media on-fabric detection rule type does not work properly with Windows 10.
921937 FortiClient cannot register to EMS using Register to EMS button in invitation email.
922818 FortiESNAC.exe crashes.
927738 EMS shows most endpoints as offline

Application Firewall

Bug ID Description
853451 FortiClient blocks PIA VPN.
853808 Excluding IPS signatures from Application Firewall (Detect and Block Exploits) is not possible.
876265 Zip Files become corrupt with Application Firewall enabled.
897207 Application Firewall blocks Microsoft 365 Defender device isolation .

FSSOMA

Bug ID Description
841316 Some FortiClient single-sign on mobility agent (FSSOMA) versions do not present client certificate to FortiAuthenticator.
862021 Local account can access Internet if FSSOMA is logged in and user locks the screen.
888721 SSOMA does not report the domain/user information to FortiAuthenticator in hybrid Azure Active Directory (AD) setup.
893985 FSSOMA creates issue with tenant ID on FortiAuthenticator in standard AD setup.

Configuration

Bug ID Description
864571 Configuration backup file contains wrong default port of 65535.
897927 FortiClient causes reboot on domain controllers .

Install and upgrade

Bug ID Description
896152 FortiClient shows Update failed – Error occurred! popup after reboot.
905132 Failed to upgrade FSSO 7.2.0 to 7.2.1 with installer that FortiClientSSOConfigurationTool created.
907340 Telemetry connection requires reboot after install.
915493 Reboot popup does not display.
926815 Host_verification_xml is missing after upgrading FortiClient 7.2.0 to 7.2.1.

Logs

Bug ID Description
923245 FortiClient logs do not include time zone .
935428 Frequent log floods other logs in FortiTray and makes debugging difficult.
945992 Diagnostic result is missing FortiClient (Windows) local log.

Zero Trust tags

Bug ID Description
928574 Logged in Domain tags do not work for Azure AD domains.
931490 ZTNA tag is not removed after vulnerability is resolved.
932828 Registry key ZTNA tag does not work when comparing DWORD type data.
911533 AD group ZTNA tag does not calculate on EMS and FortiClient.
919595 ZTNA tag rule does not work for Bitlocker disk encryption.

Vulnerability Scan

Bug ID Description
908266 FortiClient fails to detect vulnerabilities due to FCM skipping certain VIDs when scanning.
920439 Vulnerability scan reports excluded applications.
944404 Upgrade OpenSSL to 3.1.2: third party component upgrade required for security reasons.

Remote Access

Bug ID Description
702764 IPsec VPN connection fails with error: Certificate Was Not Loaded.
800934 DH group settings are not read-only for tunnel that EMS pushed.
801747 New XML tag <block_outside_dns> should be configured per-tunnel.
811458 Connecting to SSL VPN fails after installing Windows update KB5013942.
824165 SSL VPN reconnection does not work when using turn-based FortiClient connection vs. PPP method.
838231 Some users fail when using SAML authentication with SSL VPN.
851093 IPv6 DNS requests do not work.
855836 Remote VPN is visible when on-fabric when it should be hidden.
858696 FortiClient (Windows) cannot connect to SSL VPN with SAML via Satellite ISP.
886928 VPN before logon displays FortiClient credentials prompt if using user@domain.local format for username.
893958 FortiClient (Windows) does not support autoconnect in this session (CREDENTIALPROVIDER).
904923 SSL VPN with external DHCP servers requires DHCP option 12 hostname.
905354 Split tunnel with SSL VPN does not work.
906617 SSL VPN with certificate and token does not work as expected when connecting from tray icon in Windows 10 x64.
907361 IPsec VPN IKE v1 and v2 blocking IPv6 does not work.
907518 FortiClient can connect to VPN without proper remote secure access tag.
909699 Autoconnect only when off-net fails to connect if remote gateway network is down then up.
912255 SSL VPN stays connected even though there is no network connection to the VPN gateway when DTLS is enabled.
914414 When VPN before logon is configured, FortiClient does not initiate SSL VPN when Use Windows Credentials is enabled.
918669 Single user mode VPN disconnects if user locks then unlocks Windows.
920805 With multifactor authentication enabled, SSL VPN may fail to work.
920870 GUI does not support encryption as NCSC support defines.
923869 FortiClient retries multiple times to connect to VPN with Azure AD autologin when user belongs to more than 100 groups.
925710 For split tunnel exclusions, local routes are added with incorrect next hop on multihomed devices.
926174 DNS has delays on SSL VPN with Same as client system DNS error and DNS server is unreachable over VPN.
926774 Azure SAML VPN fails to autoconnect after machine wakes from hibernation.
927083, 937347 SAML login window does not come up when clicking SAML Login button.
927825 Host check for firewall does not work with FortiOS 7.0.12.
929177 IPsec VPN IKE v2 with preshared key or certificate-based with EAP enabled fails to connect.
931326 Invalid server address or port number. error occurs during upgrade.
931680 VPN before logon on Windows 11 build 7129 does not work as expected.
938746 Secure remote access with SAML tries to connect when it should be blocked.
943208 FortiClient (Windows) continuously autoconnects after manual disconnection.
945056 FortiClient (Windows) does not save Azure SAML authentication cookies in local storage and is missing SAML_VPN_COOKIES key.
947956 FortisslVPNdaemon.exe indexes the FortiClient installed location on port 8053.
950199 FortiClient (Windows) sends no DTLS encrypted alert to FortiGate when disconnecting SSL VPN DTLS tunnel.
950815 SSL VPN SAML login fails to work when using Okta for initial authentication.
951164 FortiClient (Windows) does not save SAML login credentials when Save Password is enabled.
953853 SSL VPN SAML login shows black login page if FortiClient (Windows) cannot reach IdP.

Malware Protection and Sandbox

Bug ID Description
716547 AV and Sandbox do not support combination of wildcard and path variable exclusions.
875930 FortiClient fails to quarantine a specific malware-infected dll file in Exchange Server.
893530 FortiClient reports the endpoint as not having third-party antivirus when Microsoft Defender is active.
893964 FortiClient cannot quarantine files located in a network-shared folder.
894638 FortiClient shows to kill 1426161032.exe twice for W32/Filecoder.CL!tr.ransom.
903614 Number of blocked exploit count is inconsistent with EMS.
907006 FortiClient console closes automatically when FIPS is enabled through CLI or EMS-created installer.
907331 FortiClient cannot create exception for NetSupport Manager.
911335 Removable media blocks duplicate USB device with same 'driverkeyname:' & 'device_property_classguid:'.
911521 Sandbox Detection shows double count of executed samples.
913701 Antiransomware feature fails to decrypt MSIL/Filecoder.AKJ!tr.ransom.
917941 Sandbox exclusions do not work for shared drives.
919920 FortiClient does not automatically restore previously allowlisted samples when FortiSandbox rescans them.
921366 Recorder device is inaccessible with removable media access (RMA) enabled.
923470 RMA modifies NoDriveTypeAutoRun (sets value 44) registry key.
926335 Sandbox include and exclude lists do not work.
926383 When realtime protection is enabled, logon takes around two to three minutes.
929900 FortiClient does not recognize HP docking station.
930398 USB exception rule with specific vendor ID and PID does not work.
931816 FortiClient (Windows) reports detected ransomware to Sandbox Detection.
934389 Sandbox fails to quarantine or block files in network drive.
937971 Sandbox Alert & Notify does not behave correctly.

Zero Trust telemetry

Bug ID Description
911495 FortiClient fails to autoregister to FortiClient Cloud due to Telemetry key mismatch.
922757 ZTNA registry tag rule crashes FortiNSNAC and causes FortiClient to fail to sync EMS profile and deregister.
953263 FortiESNAC process has memory leak.
953521 Feature shows as hidden when EMS does not configure it being hidden.

Deployment and installers

Bug ID Description
942984 EMS shows wrong scheduled time under endpoint details page for endpoint user-scheduled FortiClient (Windows) deployment.

Endpoint management

Bug ID Description
904348 FortiClient (Windows) and EMS detect encrption status as not enabled when only one hard disk has encryption (Bitlocker) enabled.

PAM

Bug ID Description
864571 Backup configuration contains wrong default port of 65535.
868822 PAM does not support some video parameters such as resolution, color, and so on.
905506 Recording shows black screen for SQL Server Management Services.
908671 PAM doe snot include private HTTP header (x-complete: true) to signal the file is finished uploading.
909164 PAM does not support live streaming.
912655 FortiPAM secret launchers do not launch correctly when accessing FortiPAM via external DNAT.
914874 FortiClient PAM component does not report that video monitoring has stopped.
917230 If some CLI launch (mysql shell) closes quickly, PAM GUI keep loading for 15 seconds , then response error displays.
918352 Client executable integrity check.
918486 No video-Finish received in FortiPAM.
930761 „Unchecked runtime.lastError: The message port closed before a response was received.” error displays with PAM agent.
931648 FortiClient PAM is not disabled in the MSI MST when it is disabled in the installer package.
939187 PAM session recorded video from extension has incorrect length because information is missing in mpd file.
946105 PAM does not include FortiClient version, OS type, and build number.

FortiSASE

Bug ID Description
930967 FortiClient (Windows) cannot establish FortiSASE VPN with Azure SAML AD user and Windows Defender blocks FortiClientConsole.exe.

Other

Bug ID Description
797264 FortiClient (Windows) cannot update signatures from FortiManager.
833661 Blue screen of death (BSOD) occurs with FortiClient installed.
874474 FortiClient does not start update_task as scheduled or update ISDB signature.
893820 Add new Forensics agent to FDS.
896137 DesktipID does not work after installing FortiClient.
900691 Forticlient on Windows Server 2019 causes BSOD when copying files to and from Citrix Share.
909504 Use industry standards in names and labels.
915119 Localization into supported languages.
915168 Memory leak in fcaptmon process.
919027 User cannot shut down FortiClient (Windows) after deregistering from and EMS that has Require Password to Disconnect From EMS enabled.
922413 fortitcs.exe thread and handle leak.
931821 Orchestrator.exe pings 1.1.1.1.
932433 FortiClient binds Forensic and VCM features.
933608 FortiAptFilter.sys causes BSOD on Windows 11 with FortiClient.
937175 Windows Firewall shows alert regarding FortiClient.exe.
937215 ftsvnic.sys causes BSOD.
938181 ZTNA daemon takes high CPU and keep switching between its log files.
940025 FortiClient does not have the latest ICDB signature version in the installed build.
948228 FortiShield blocks its own process (fmon).
954687 FortiSSLVPNdaemon crash observed in the auto test system.
955237 FortiSettings crashes when FortiClient Settings configuration is selected/unselected in GUI.

Common Vulnerabilities and Exposures

Bug ID Description
957936 FortiClient for Windows no longer is vulnerable to exposing sensitive information in the agent log.

 

Notatki producenta: FortiClient 7.2.2 ( Windows)

Pozdrawiamy,

Zespół B&B
Bezpieczeństwo w biznesie

Post Views: 1 853

7.2.2 FortiClient

Poprzedni artykułVMware vCenter Server 7.0 Update 3Następny artykuł VMware vSphere Replication 8.8.0

Najnowsze

FortiAnalyzer 7.6.38 maja 2025
FortiManager 7.6.330 kwietnia 2025
FortiMail 7.6.322 kwietnia 2025

Kategorie

  • Acronis
  • Aktualności
  • Bez kategorii
  • ESET
  • F-Secure
  • FortiAnalyzer
  • FortiAP
  • FortiAuthenticator
  • FortiClient
  • FortiDeceptor
  • FORTIGATE
  • FORTIMAIL
  • FortiManager
  • FortiNAC
  • FortiSIEM
  • FORTISWITCH
  • FortiWeb
  • NAKIVO
  • Proget
  • Qnap
  • Stormshield
  • Szkolenia
  • Veeam
  • VMware
  • WithSecure

Tagi

6.0.6 6.2.2 6.2.7 6.4.0 6.4.4 6.4.5 6.4.8 7.0.0 7.0.2 7.0.5 7.2.0 7.2.2 ems Eset eset endpoint antivirus eset endpoint security ESET Inspect ESET Protect ESET Protect Cloud F-Secure FMG FortiAnalyzer forti analyzer FortiAP fortiap-w2 FortiAuthenticator FortiClient FortiClientEMS forticlient ems FortiGate FortiMail FortiManager FortiNAC Fortinet FortiOS FortiSIEM FortiSwitch FortiWeb vCenter vCenter Server VMware VMware ESXi vmware esxi 8.0 vmware vcenter VMware vCenter Server

MENU

  • Start
  • O nas
  • Produkty
  • Usługi
    • Szkolenia
    • Cyberbezpieczny Samorząd
    • Audyt bezpieczeństwa informacji
      • Testy penetracyjne
      • Testy ataków socjotechnicznych
    • Audyt konfiguracji Fortigate
    • Prezentacje
    • Wdrożenia
  • Blog techniczny
  • Pomoc
  • Kariera
  • Kontakt

BLOG TECHNICZNY

FortiAnalyzer 7.6.38 maja 2025
FortiManager 7.6.330 kwietnia 2025
FortiMail 7.6.322 kwietnia 2025

KONTAKT

biuro@b-and-b.plhttps://www.b-and-b.pl
8:00-16:00
RODO | POLITYKA PRYWATNOŚCI
OGÓLNE WARUNKI REKLAMACJI

BEZPIECZEŃSTWO W BIZNESIE 2025 - wszystkie prawa zastrzeżone

MENU

  • Start
  • O nas
  • Produkty
  • Usługi
    • Szkolenia
    • Cyberbezpieczny Samorząd
    • Audyt bezpieczeństwa informacji
      • Testy penetracyjne
      • Testy ataków socjotechnicznych
    • Audyt konfiguracji Fortigate
    • Prezentacje
    • Wdrożenia
  • Blog techniczny
  • Pomoc
  • Kariera
  • Kontakt

BLOG TECHNICZNY

FortiAnalyzer 7.6.38 maja 2025
FortiManager 7.6.330 kwietnia 2025
FortiMail 7.6.322 kwietnia 2025

Kontakt

+48 500-413-313
biuro@b-and-b.pl
8:00-16:00
Add new entry logo

Korzystamy z plików cookies lub podobnych technologii, by lepiej dopasować treści na stronie do Twoich potrzeb. W każdej chwili możesz zmienić ustawienia cookies. Polityka prywatności

Akceptuję Odmów
Cookies are small text files that can be used by websites to make a user's experience more efficient. The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission. This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.
  • Always Active
    Necessary
    Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

  • Marketing
    Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.

  • Analytics
    Analytics cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

  • Preferences
    Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.

  • Unclassified
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.