Описание
A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Windows "security alert" dialog thereby popping up when the "VPN before logon" feature is enabled and an untrusted certificate chain.
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- ExploitMitigationThird Party Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- ExploitMitigationThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.4.3 (включая)
Одно из
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*
cpe:2.3:a:fortinet:forticlient:5.6.0:*:*:*:*:windows:*:*
EPSS
Процентиль: 79%
0.01272
Низкий
8.1 High
CVSS3
7.6 High
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 8.1
github
больше 3 лет назад
A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Windows "security alert" dialog thereby popping up when the "VPN before logon" feature is enabled and an untrusted certificate chain.
EPSS
Процентиль: 79%
0.01272
Низкий
8.1 High
CVSS3
7.6 High
CVSS2
Дефекты
NVD-CWE-noinfo