CVE-2017-7344
Summary
| CVE | CVE-2017-7344 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-14 18:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Windows "security alert" dialog thereby popping up when the "VPN before logon" feature is enabled and an untrusted certificate chain. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fortinet | Forticlient | 5.6.0 | All | All | All |
| Application | Fortinet | Forticlient | 5.6.0 | All | All | All |
| Application | Fortinet | Forticlient | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2017-7344 Fortinet FortiClient Windows privilege escalation at logon – Intrinsec | MISC | securite.intrinsec.com | Exploit, Mitigation, Third Party Advisory |
| Fortinet FortiClient CVE-2017-7344 Privilege Escalation Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Gain Windows privileges with FortiClient vpn before logon and untrusted certificate | FortiGuard | CONFIRM | fortiguard.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.