CVE-2024-40586
An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSS
Severity
Medium 6.3
CVSS 3.1
Exploited
Not listed
EPSS
0.002
16.4th percentile
Discovered by
Third party
Vendor advisory field
Published
Feb 11, 2025
Assigned by fortinet
Description
An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.
Weakness: CWE-284
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiClientWindows
Credit
Fortinet is pleased to thank Erwin Chan for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please upgrade to FortiClientWindows version 7.4.1 or above Please upgrade to FortiClientWindows version 7.2.7 or above Please upgrade to FortiClientWindows version 7.0.14 or above