CVE-2021-36183: High severity fortinet forticlient ssl vpn vulnerability
Published Nov 2, 2021
·Updated
An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.
Affected Software
2 affected components
Fortinet FortiClient Windows>=6.4.0<=6.4.2
Fortinet FortiClient Windows>=7.0.0<=7.0.1
Event History
Nov 2, 2021
CVE Published
via MITRE·06:41 PM
Data Sourced
via MITRE·06:41 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36183.
2
What is the severity of CVE-2021-36183?
The severity of CVE-2021-36183 is high with a CVSS score of 7.8.
3
Which software versions are affected by CVE-2021-36183?
FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below are affected by CVE-2021-36183.
4
How can an attacker exploit CVE-2021-36183?
A local unprivileged attacker can escalate their privileges to SYSTEM by exploiting the named pipe responsible for Forticlient updates.
5
Is there a fix available for CVE-2021-36183?
Yes, it is recommended to update FortiClient for Windows to a version that is not affected by CVE-2021-36183.