216.73.216.233

CVE-2024-36513

· Published 12/11/2024 19:15 · Modified 14/11/2024 20:35

Labels: CVE-2024-36513 2024-11-12CVE-2024-36513CWE-270[email protected]

Essential information

Published
12/11/2024 19:15
Modified
14/11/2024 20:35
Author
Creator
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CVSS metrics

Description

A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fortinet / forticlient cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*
fortinet / forticlient cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*
fortinet / forticlient cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*

References