F‑Secure Support Tool (fsdiag) embedded within various F‑Secure products for Microsoft Windows can be abused to execute arbitrary commands on the system.
STATUS: Fixed
ACTION REQUIRED: F‑Secure Business Suite administrator need to apply the hotfix manually. All other products are automatically updated.
RISK LEVEL: Medium
FIX: In all other environments fix has been published through the automatic update channel.
F‑Secure VPN
F‑Secure Internet Security
F‑Secure KEY
F‑Secure Internet Security / Anti-Virus
All supported Windows version for the affected product
An arbitrary code execution vulnerability was found in the F‑Secure Support Tool. A standard user can craft a special configuration file, which when run by administrator can execute any commands.
This issue was reported to F‑Secure through the Vulnerability Reward Program. No known exploit or attack has been seen in the wild.
User interaction is required prior to exploitation.
Administrative privileges is required to run arbitrary scripts/commands in the system.
F‑Secure Corporation would like to thanks Nasreddine Bencherchali (@nas_bench) for bringing this issue to our attention.
Date Issued: 09-Mar-2022