CVE-2024-40586: Medium severity fortinet forticlient virtual private network vulnerability
An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40586?
CVE-2024-40586 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2024-40586?
To fix CVE-2024-40586, update FortiClient to version 7.4.1 or later, which addresses the improper access control issue.
What versions of FortiClient are affected by CVE-2024-40586?
CVE-2024-40586 affects FortiClient Windows versions 7.4.0, 7.2.6 and below, as well as 7.0.13 and below.
Can CVE-2024-40586 be exploited remotely?
No, CVE-2024-40586 requires local access, as it involves privilege escalation through the FortiSSLVPNd service.
What type of vulnerability is CVE-2024-40586?
CVE-2024-40586 is categorized as an Improper Access Control vulnerability, specifically related to privilege escalation.