Fortinet udostępnił aktualizację dla produktu FortiClient o numerze wersji 7.0.9. Nowa wersja aplikacji rozwiązuje problemy z synchronizacją pomiędzy klientem a serwerem EMS, poprawiono funkcjonalność filtrowania sieci Web oraz rozwiązano sporo problemów związanych z tunelami IPsec. Wprowadzono również małe poprawki eliminujące problemy z utratą licencji po aktualizacji klienta, problemy z aktualizacją sygnatur, oraz niespodziewane przerwanie działania procesów związanych z FortiClientem. Warto również wspomnieć, że FortiClient 7.0.9 jest wolny od podatności: CVE-2022-42470, CVE-2022-40682, CVE-2022-43946
Aktualnie wspierane systemy:
Rozwiązane problemy:
Endpoint control
| Bug ID | Description |
|---|---|
| 899960 | FortiESNAC process stops after switching between two FortiSASE EMS services. |
GUI
| Bug ID | Description |
|---|---|
| 892171 | GUI gets blank screen and cannot connect to FortiSASE SSL VPN. |
Install and upgrade
Web Filter and plugin
| Bug ID | Description |
|---|---|
| 826697 | Web Filter affects ConnectWise Automate. |
| 870895 | Web Filter blocks Docker pull. |
| 892204 | Web Filter blocks traffic for signing into some HTTP web servers. |
| 900083 | Upgrading FortiClient (Windows) to 7.0.8 causes problems accessing HTTP site. |
| 907534 | After clicking popup, FortiClient does not open the window to enable Allow in Incognito. |
Zero Trust Telemetry
| Bug ID | Description |
|---|---|
| 886203 | Telemetry stuck in syncing state. |
| 911495 | FortiClient (Windows) fails to autoregister to FortiClient Cloud due to Telemetry key mismatch. |
Remote Access
Malware Protection and Sandbox
| Bug ID | Description |
|---|---|
| 833264 | Antiexploit blocks Chrome without sharing payload details. |
| 858120 | Read/write restrictions over FortiClient pipe objects are improper. |
| 903614 | Number of blocked exploit count is mismatched on EMS. |
| 917941 | Sandbox exclusions do not work for shared drives. |
ZTNA connection rules
| Bug ID | Description |
|---|---|
| 911024 | Host keeps requesting new certificates after logging in to Windows. |
| 919540 | Password can be seen in plain text format in GUI logs with basic authentication enabled. |
License
| Bug ID | Description |
|---|---|
| 904835 | FortiClient (Windows) loses license after upgrade. |
Logs
| Bug ID | Description |
|---|---|
| 923245 | Logs do not include timezone. |
Upgrade
| Bug ID | Description |
|---|---|
| 816531 | FortiClient (Windows) signatures do not get updated. |
Administration
| Bug ID | Description |
|---|---|
| 869731 | scheduler.exe crashes sometimes. |
| 869845 | FortiClient (Windows) daemon crashes. |
FSSO agent
| Bug ID | Description |
|---|---|
| 851036 | FortiClient does not send IP address using mobility agent to FortiAuthenticator when on-premise. |
Other
| Bug ID | Description |
|---|---|
| 861070 | User can kill FortiClient (Windows) processes when FortiShield is running. |
| 874474 | update_task does not start as scheduled and ISDB signature is not updated. |
| 893195 | FortiTray crashes on 32- and 64-bit operating systems. |
| 896137 | DesktipID application does not work after installing FortiClient. |
Common Vulnerabilities and Exposures
| Bug ID | Description |
|---|---|
| 838208 | FortiClient (Windows) 7.0.9 is no longer vulnerable to the following CVE References:
Visit https://fortiguard.com/psirt for more information. |
| 840897 | FortiClient (Windows) 7.0.9 is no longer vulnerable to the following CVE References:
Visit https://fortiguard.com/psirt for more information. |
| 845295 | FortiClient (Windows) 7.0.9 is no longer vulnerable to the following CVE References:
Visit https://fortiguard.com/psirt for more information. |
Znane problemy:
Application Firewall
| Bug ID | Description |
|---|---|
| 717628 | Application Firewall causes issues with Motorola RMS high availability client. |
| 814391 | FortiClient Cloud application signatures block allowlisted applications. |
| 823292 | FortiClient cannot connect to JVC wireless display. |
| 827788 | Threat ID is 0 on Firewall Events. |
| 842534 | After upgrade to FortiClient (Windows) 7.0.7, Application Firewall blocks internal webpage. |
| 844997 | FortiClient sees several packet losses on different internal resources after connecting telemetry. |
| 853451 | FortiClient blocks PIA VPN. |
| 853808 | FortiClient (Windows) blocks Veeam with messages related to Remote.CMD.Shell and VeeamAgent.exe. |
| 860062 | Application Firewall slows down opening Microsoft Active Directory (AD) Users and Computers application. |
| 884911 | FortiClient detects IntelliJ IDEA Community Edition 2021.2.2 as Java.Debug.Wire.Protocol.Insecure.Configuration. |
| 891789 | Application Firewall blocks CREO Management tool software. |
| 902866 | Application Firewall does not block Google Drive. |
| 907089 | FortiClient continues blocking MS.Windows.HTTP.Protocol.Stack.CVE-2022-21907.Code.Execution by application firewall. |
Endpoint control
Endpoint management
| Bug ID | Description |
|---|---|
| 760816 | Group assignment rules based on IP addresses do not work when using split tunnel. |
| 786738 | Anti-Ransomware Events tab is visible after disabling from Feature Select. |
| 904348 | FortiClient (Windows) and EMS detect encryption status as not enabled when only one hard disk has encryption (Bitlocker) enabled. |
GUI
| Bug ID | Description |
|---|---|
| 767998 | Free VPN-only client includes Action for invalid EMS certificate in settings. |
| 811742 | FortiClient (Windows) does not hide software update options when registered to EMS (regression). |
| 826895 | FortiClient ignores the listing order of the configured VPN connections in the GUI and tray. |
| 827394 | FortiClient does not report profile change update in Notifications. |
| 902595 | SAML prompt flashes on autoconnect. |
| 934351 | FortiSASE VPN gets stuck at wrong VPN connection status until FortiClient console restarts from sleep wakeup or network interruption.Workaround: Restart FortiClient console. |
Install and upgrade
| Bug ID | Description |
|---|---|
| 749331 | Windows Security setting in Windows displays FortiClient is snoozed when FortiEDR is installed. |
| 769639 | FortiDeviceGuard is not installed on Windows Server 2022. |
| 783690 | Reboot prompt does not display after user login. |
| 820672 | ZTNA driver FortiTransCtrl.sys fails to start on Windows Server 2016. |
| 867982 | Blank certificate pops up when upgrading. |
Zero Trust tags
| Bug ID | Description |
|---|---|
| 782394 | ZTNA user identity tags do not work. |
| 819120 | Zero trust tag rule for AD group does not work when registering FortiClient to EMS with onboarding user. |
| 911533 | EMS and FortiClient (Windows) do not calculate AD group ZTNA tag. |
Configuration
| Bug ID | Description |
|---|---|
| 730415 | FortiClient backs up configuration that is missing locally configured ZTNA connection rules. |
User and authentication
| Bug ID | Description |
|---|---|
| 765184 | RADIUS authentication failover between two servers for high availability does not work well. |
Performance
| Bug ID | Description |
|---|---|
| 749348 | Performance issues after upgrade. |
Zero Trust Telemetry
| Bug ID | Description |
|---|---|
| 683542 | FortiClient (Windows) fails to register to EMS if registration key contains a special character: ” !”#$%&'()*+,-./:;<=>?@[\]^_`{|}~”. |
| 792703 | FortiClient (Windows) cannot connect to FortiClient Cloud. |
Malware Protection and Sandbox
| Bug ID | Description |
|---|---|
| 760073 | FortiDeviceGuard could not be installed on Windows Server through installer. |
| 793926 | FortiShield blocks spoolsv.exe on Citrix virtual machine servers. |
| 825732 | SIM-card-slot UEFI feature slows down Windows logon when connected to VPN. |
| 828862 | FortiClient does not allow virtual CD-ROM device. |
| 831560 | GUI shows ransomware quarantined files after restoration via EMS. |
| 837638 | Identifying malware and exploits using signatures received from FortiSandbox does not work. |
| 844988 | FortiClient (Windows) does not block USB drive if attempting to copy contents even if WPD/USB is set to be blocked in profile. |
| 857041 | Windows 10 security center popup shows both FortiClient and Windows Defender are turned off. |
| 863802 | EMS and FortiClient (Windows) cannot detect SentinelOne even if they have product on operating system level. |
| 872970 | Bubble notifications do not appear when inserting USB drive in endpoint machine. |
| 876925 | Antiexploit protection blocks Microsoft Signing application in Chrome. |
| 882904 | FortiClient (Windows) does not include XML option to decide if FortiClient (Windows) should be snoozed or allowed to run side by side with FortiEDR. |
| 903371 | FortiClient causes an unhandled exception on third party process when AV components are installed but disabled. |
| 915300 | FortiClient (Windows) detects file included in exception as malware. |
| 916958 | FortiClient (Windows) cannot detect a virus-infected file. |
| 919007 | On-deman scan for mapped drives is not possible. |
| 923470 | Removable media access modifies registry key NoDriveTypeAutoRun (sets value 44). |
| 925850 | RTP stop downloading file on Windows 11. |
| 926155 | If Malware Protection is enabled, OS hangs up during export of .MOV file to Telestream switch. |
| 926383 | When RTP is enabled, logon takes two to three minutes. |
| 926906 | Printing from a web browser fails if web downloads are enabled under Sandbox. |
Remote Access
Vulnerability Scan
| Bug ID | Description |
|---|---|
| 741241 | FortiClient (Windows) finds vulnerabilities for uninstalled software. |
| 795393 | EMS does not remove vulnerability events after successful patch. |
| 849485 | FortiClient wrongly detects AnyDesk vulnerabilities CVE-2021-44426 and CVE-2021-44425. |
| 869253 | FortiClient detects vulnerability when the required KB is installed. |
| 908266 | FortiClient fails to detect vulnerabilities possibly due to FCM skipping certain VIDs when scanning. |
Logs
| Bug ID | Description |
|---|---|
| 820067 | FortiClient forwards logs despite being completely disabled. |
| 849043 | SSL VPN add/close action does not show on FortiGate Endpoint Event section. |
| 876810 | FortiClient does not indicate VPN user in logs when the connection succeeds. |
Web Filter and plugin
| Bug ID | Description |
|---|---|
| 776089 | FortiClient (Windows) does not block malicious sites when Web Filter is disabled. |
| 812207 | Blocked web client shows dropped connection message instead of URL blocked message. |
| 836906 | After FortiClient install, extended uptime results in audio cracking. |
| 871325 | Web Filter breaks DW Spectrum. |
| 904840 | When a user is doing device recovery in iTunes, error 3500 displays. |
| 909060 | User cannot update information on internal portal with Web Filter active. |
Avatar and social network login
| Bug ID | Description |
|---|---|
| 878050 | Avatar does not update on FortiGate dashboards and FortiGate cannot show updated information. |
Multitenancy
| Bug ID | Description |
|---|---|
| 780308 | EMS automatically migrates endpoints to default site. |
ZTNA connection rules
FSSOMA
| Bug ID | Description |
|---|---|
| 841316 | Some SSOMA versions do not present client certificate to FortiAuthenticator. |
| 862021 | Local account can access Internet if FSSOMA is logged in and AD user locks the screen. |
| 909844 | User FSSO sessions drop earlier than expected. |
Onboarding
| Bug ID | Description |
|---|---|
| 811976 | FortiClient (Windows) may prioritize using user information from authentication user registered to EMS. |
| 819989 | FortiClient (Windows) does not show login prompt when installed with installer using LDAP/local verification. |
License
| Bug ID | Description |
|---|---|
| 830899 | FortiClient connected to EMS loses license. |
| 874676 | EMS tags endpoint with existing ZTNA host tags for vulnerability and AV after EMS administrator updates EMS license from Endpoint Protection Platform to Remote Access. |
Endpoint policy and profile
| Bug ID | Description |
|---|---|
| 889517 | EMS fails to assign the correct endpoint policy and shows FortiClient as out-of-sync despite the client syncing. |
Other
| Bug ID | Description |
|---|---|
| 780651 | FortiClient (Windows) does not update signatures on expected schedule. |
| 797264 | FortiClient (Windows) cannot update signatures from FortiManager. |
| 834389 | FortiClient (Windows) has incompatibility with Fuji Nexim software. |
| 915185 | Newer GUI elements are not translated into listed supported languages. |
| 919017 | FortiClient (Windows) changes installer checksum/hash for Baramundi management agent. |
Notatki producenta: FortiClient 7.0.9(windows)
Notatki producenta: FortiClient 7.0.9(macOS)
Pozdrawiamy,
Zespół B&B
Bezpieczeństwo w biznesie
