Fortinet FortiClient
cpe:2.3:a:fortinet:forticlient:*:*:*:*:windows:*:*
- >= 7.4.0, <= 7.4.4
- >= 7.2.0, <= 7.2.12
- ~7.0
A vulnerability allowing improper link resolution before file access has been identified in Fortinet FortiClient for Windows, specifically in versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.12, and all versions of 7.0. This vulnerability may enable a local low-privilege attacker to perform arbitrary file writes with elevated permissions by sending crafted messages through named pipes.
Exploitation of this vulnerability could lead to unauthorized file writes with elevated permissions, potentially allowing for further exploitation or manipulation of the system.
Users can upgrade to FortiClient Windows 7.4.5 or above, FortiClient Windows 7.2.13 or above, or migrate to a fixed release if using FortiClient Windows 7.0.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.