8.8
CVE-2024-36513
- EPSS 0.02%
- Published 12.11.2024 19:15:10
- Last modified 14.11.2024 20:35:26
- Source psirt@fortinet.com
- Teams watchlist Login
- Open Login
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
Data is provided by the National Vulnerability Database (NVD)
Fortinet ≫ FortiClient SwPlatformwindows Version >= 6.4.0 <= 6.4.10
Fortinet ≫ FortiClient SwPlatformwindows Version >= 7.0.0 < 7.0.13
Fortinet ≫ FortiClient SwPlatformwindows Version >= 7.2.0 < 7.2.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.048 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
psirt@fortinet.com | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
|
CWE-270 Privilege Context Switching Error
The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.