An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.
2021-11-02T19:15:07.830
2024-11-21T06:13:16.457
Modified
CVSSv3.1: 7.4 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | forticlient | ≤ 6.4.2 | Yes |
Application | fortinet | forticlient | ≤ 7.0.1 | Yes |