CVE Vulnerabilities

CVE-2021-36183

Published: Nov 02, 2021 | Modified: May 03, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.

Affected Software

Name Vendor Start Version End Version
Forticlient Fortinet 6.4.0 (including) 6.4.2 (including)
Forticlient Fortinet 7.0.0 (including) 7.0.1 (including)

References