A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Forticlient | Fortinet | 6.4.0 (including) | 6.4.10 (including) |
Forticlient | Fortinet | 7.0.0 (including) | 7.0.13 (excluding) |
Forticlient | Fortinet | 7.2.0 (including) | 7.2.5 (excluding) |