CVE-2024-50564

A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interproce

Severity
Low 3.2
CVSS 3.1
Exploited
Not listed
EPSS
0.002
12.1th percentile
Discovered by
Not disclosed
Published
Jan 14, 2025
Assigned by fortinet

Description

A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped.

Weakness: CWE-321

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiClientWindows

Vendor remediation

Please upgrade to FortiClientWindows version 7.4.1 or above