PT-2024-27041 · Fortinet · Forticlientwindows

CVE-2024-36513

·

Published

2024-11-12

·

Updated

2025-01-12

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiClient Windows versions 7.2.4 and below FortiClient Windows version 7.0.12 and below FortiClient Windows version 6.4
Description A privilege context switching error vulnerability in FortiClient Windows may allow an authenticated user to escalate their privileges via lua auto patch scripts. This issue is related to errors in switching the context of privileges.
Recommendations For FortiClient Windows versions 7.2.4 and below, update to a version above 7.2.4 to resolve the issue. For FortiClient Windows version 7.0.12 and below, update to a version above 7.0.12 to resolve the issue. For FortiClient Windows version 6.4, consider upgrading to a newer version to mitigate the risk of exploitation, as all versions of 6.4 are affected. As a temporary workaround, consider restricting access to lua auto patch scripts until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01171
CVE-2024-36513

Affected Products

Forticlientwindows