Improper Access Control in FortiClient Windows by Fortinet
CVE-2024-40586
6.3MEDIUM
What is CVE-2024-40586?
An improper access control vulnerability exists in FortiClient Windows that could enable a local user to escalate their privileges. This can occur via the FortiSSLVPNd service pipe when versions 7.4.0, 7.2.6 and earlier, or 7.0.13 and earlier are used, leaving systems susceptible to unauthorized access and control.
Affected Version(s)
FortiClientWindows 7.4.0
FortiClientWindows 7.2.0 <= 7.2.6
FortiClientWindows 7.0.3 <= 7.0.13