← Zuruck zu CVEs
CVE-2024-36513
HIGH8.2
Beschreibung
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
CVE Details
CVSS v3.1 Bewertung8.2
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
AngriffsvektorLOCAL
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionREQUIRED
Veroffentlicht11/12/2024
Zuletzt geandert11/14/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
fortinet:forticlient
Schwachen (CWE)
CWE-270
Referenzen
https://fortiguard.fortinet.com/psirt/FG-IR-24-144(psirt@fortinet.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.