CVE-2021-41031

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
18/07/2022
Last modified:
25/07/2022

Description

A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for FortiESNAC service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* 6.2.0 (including) 6.2.9 (including)
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* 6.4.0 (including) 6.4.6 (including)
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* 7.0.0 (including) 7.0.2 (including)


References to Advisories, Solutions, and Tools