Privilege escalation vulnerability

Summary

An improper authorization vulnerability [CWE-285] in FortiClient for Windows may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.

Affected Products

FortiClientWindows version 6.4.2 and below.
ForticlientWindows version 7.0.1 and below.

Solutions

Please upgrade FortiClientWindows to version 6.4.3 or above.


Please upgarde FortiClientWindows to version 7.0.2 or above.

Acknowledgement

Fortinet is pleased to thank Dimitri Gasser, Nicola Stauffer and Daniel Hulliger for reporting this vulnerability under responsible disclosure.