8.8
CVE-2024-36513
- EPSS 0.22%
- Veröffentlicht 12.11.2024 19:15:10
- Zuletzt bearbeitet 14.11.2024 20:35:26
- Erkennungen
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ FortiClient SwPlatform windows Version >= 6.4.0 <= 6.4.10
Fortinet ≫ FortiClient SwPlatform windows Version >= 7.0.0 < 7.0.13
Fortinet ≫ FortiClient SwPlatform windows Version >= 7.2.0 < 7.2.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.121 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
| Fortinet | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
|
CWE-270 Privilege Context Switching Error
The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.
https://fortiguard.fortinet.com/psirt/FG-IR-24-144