CVE Vulnerabilities

CVE-2024-36513

Privilege Context Switching Error

Published: Nov 12, 2024 | Modified: Nov 14, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.

Weakness

The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.

Affected Software

Name Vendor Start Version End Version
Forticlient Fortinet 6.4.0 (including) 6.4.10 (including)
Forticlient Fortinet 7.0.0 (including) 7.0.13 (excluding)
Forticlient Fortinet 7.2.0 (including) 7.2.5 (excluding)

Potential Mitigations

References