First published: Mon Oct 19 2020(Updated: )
An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiClient | >=6.0.0<6.2.8 | |
Fortinet FortiClient | =6.4.0 | |
Fortinet FortiClient Virtual Private Network | <=6.2.7 |
Please upgrade to FortiClient for Linux versions 6.2.8 or above. Please upgrade to FortiClient for Linux versions 6.4.1 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15934 is categorized as a critical vulnerability due to its potential to allow local privilege escalation to root.
To fix CVE-2020-15934, update FortiClient to version 6.2.8 or later, or 6.4.1 or later.
CVE-2020-15934 affects FortiClient for Linux versions 6.2.7 and below, and version 6.4.0.
CVE-2020-15934 is an execution with unnecessary privileges vulnerability in the VCM engine of FortiClient.
Yes, local users can exploit CVE-2020-15934 to elevate their privileges to root by creating a malicious script or program.