CVE Vulnerabilities

CVE-2024-36513

Privilege Context Switching Error

Published: Nov 12, 2024 | Modified: Nov 14, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.

Weakness

The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.

Affected Software

NameVendorStart VersionEnd Version
ForticlientFortinet6.4.0 (including)6.4.10 (including)
ForticlientFortinet7.0.0 (including)7.0.13 (excluding)
ForticlientFortinet7.2.0 (including)7.2.5 (excluding)

Potential Mitigations

References