QID 376020

Date Published: 2022-01-19

QID 376020: FortiClient Windows Privilege escalation Vulnerability (FG-IR-20-079)

FortiClient is a comprehensive endpoint security solution

An improper authorization vulnerability in FortiClient for Windows may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.

Affected Versions:
FortiClient for Windows Versions 7.0.1 and below.

QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.exe.

A successful attack may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Users are advised to upgrade to the latest version FortiClient 7.0.2 of the software. Latest version can be downloaded from FortiClient(Windows)
    Vendor References

    CVEs related to QID 376020

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-20-079 URL Logo www.fortiguard.com/psirt/FG-IR-20-079