First published: Tue Nov 02 2021(Updated: )
An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiClient Windows | >=6.4.0<=6.4.2 | |
Fortinet FortiClient Windows | >=7.0.0<=7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36183.
The severity of CVE-2021-36183 is high with a CVSS score of 7.8.
FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below are affected by CVE-2021-36183.
A local unprivileged attacker can escalate their privileges to SYSTEM by exploiting the named pipe responsible for Forticlient updates.
Yes, it is recommended to update FortiClient for Windows to a version that is not affected by CVE-2021-36183.