CVE-2024-36513

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/11/2024
Last modified:
14/11/2024

Description

A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* 6.4.0 (including) 6.4.10 (including)
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* 7.0.0 (including) 7.0.13 (excluding)
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* 7.2.0 (including) 7.2.5 (excluding)


References to Advisories, Solutions, and Tools