8.8
CVE-2024-36513
- EPSS 0.02%
- Veröffentlicht 12.11.2024 19:15:10
- Zuletzt bearbeitet 14.11.2024 20:35:26
- Quelle psirt@fortinet.com
- Teams Watchlist Login
- Unerledigt Login
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ FortiClient SwPlatformwindows Version >= 6.4.0 <= 6.4.10
Fortinet ≫ FortiClient SwPlatformwindows Version >= 7.0.0 < 7.0.13
Fortinet ≫ FortiClient SwPlatformwindows Version >= 7.2.0 < 7.2.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.048 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
psirt@fortinet.com | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
|
CWE-270 Privilege Context Switching Error
The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.