An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.
2025-02-11T17:15:22.683
2025-07-16T15:11:18.923
Analyzed
CVSSv3.1: 6.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | forticlient | < 7.0.14 | Yes |
Application | fortinet | forticlient | < 7.2.7 | Yes |
Application | fortinet | forticlient | 7.4.0 | Yes |