QID 376020
Date Published: 2022-01-19
QID 376020: FortiClient Windows Privilege escalation Vulnerability (FG-IR-20-079)
FortiClient is a comprehensive endpoint security solution
An improper authorization vulnerability in FortiClient for Windows may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.
Affected Versions:
FortiClient for Windows Versions 7.0.1 and below.
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.exe.
A successful attack may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.
Solution
Users are advised to upgrade to the latest version FortiClient 7.0.2 of the software. Latest version can be downloaded from FortiClient(Windows)
Vendor References
- FG-IR-20-079 -
www.fortiguard.com/psirt/FG-IR-20-079
CVEs related to QID 376020
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-20-079 |
|