PT-2024-27041 · Fortinet · Forticlientwindows
Published
2024-11-12
·
Updated
2025-01-12
·
CVE-2024-36513
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiClient Windows versions 7.2.4 and below
FortiClient Windows version 7.0.12 and below
FortiClient Windows version 6.4
Description
A privilege context switching error vulnerability in FortiClient Windows may allow an authenticated user to escalate their privileges via lua auto patch scripts. This issue is related to errors in switching the context of privileges.
Recommendations
For FortiClient Windows versions 7.2.4 and below, update to a version above 7.2.4 to resolve the issue.
For FortiClient Windows version 7.0.12 and below, update to a version above 7.0.12 to resolve the issue.
For FortiClient Windows version 6.4, consider upgrading to a newer version to mitigate the risk of exploitation, as all versions of 6.4 are affected.
As a temporary workaround, consider restricting access to lua auto patch scripts until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forticlientwindows