QID 377873
Date Published: 2023-01-12
QID 377873: FortiClient Privilege Escalation Vulnerability (FG-IR-21-190)
A relative path traversal vulnerability [CWE-23] in FortiClient for Windows may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for FortiESNAC service.
Affected Products
FortiClientWindows version 7.0.0 through 7.0.2
FortiClientWindows version 6.4.0 through 6.4.6
FortiClientWindows 6.2 all versions
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.exe.
Vulnerable version may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for FortiESNAC service.
Solution
Users are advised to upgrade to the latest version FortiClient. Please refer FG-IR-21-190 for further information.
Vendor References
- FG-IR-21-190 -
www.fortiguard.com/psirt/FG-IR-21-190
CVEs related to QID 377873
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-190 |
|