Vulnerability Details CVE-2021-36183
An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.5%
CVSS Severity
CVSS v3 Score 7.4
CVSS v2 Score 7.2
Products affected by CVE-2021-36183
-
cpe:2.3:a:fortinet:forticlient:6.4.0
-
cpe:2.3:a:fortinet:forticlient:6.4.1
-
cpe:2.3:a:fortinet:forticlient:6.4.2
-
cpe:2.3:a:fortinet:forticlient:7.0.0
-
cpe:2.3:a:fortinet:forticlient:7.0.1