cbcvebase.
CVE-2020-15934
published 2024-12-19

CVE-2020-15934: An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.5th percentile
An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine.

Affected

8 ranges
VendorProductVersion rangeFixed in
fortinetforticlient
fortinetforticlient
fortinetforticlient>= 6.0.0 < 6.2.86.2.8
fortinetforticlientlinux
fortinetforticlientlinux
fortinetforticlientlinux6.0.0 – 6.0.6
fortinetforticlientlinux6.2.0 – 6.2.4
fortinetforticlientlinux6.2.6 – 6.2.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.