CVE-2024-36513
published 2024-11-12CVE-2024-36513: A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may…
PriorityP345high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.22%
12.4th percentile
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | 6.4.0 – 6.4.10 | — |
| fortinet | forticlient | >= 7.0.0 < 7.0.13 | 7.0.13 |
| fortinet | forticlient | >= 7.2.0 < 7.2.5 | 7.2.5 |
| fortinet | forticlientwindows | 6.4.0 – 6.4.10 | — |
| fortinet | forticlientwindows | 7.0.0 – 7.0.12 | — |
| fortinet | forticlientwindows | 7.2.0 – 7.2.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0...
vendor_fortinet·2024-11-12·CVSS 8.2
CVE-2024-36513 [HIGH] CWE-270 A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0...
FG-IR-24-144: A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0...
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
CVEs: CVE-2024-36513
CWEs: CWE-270
CVSS: 8.2 (high)
Affected products: FortiClient
GHSA
GHSA-9m68-hrx9-5wfc: A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7
ghsa_unreviewed·2024-11-12
CVE-2024-36513 [HIGH] CWE-270 GHSA-9m68-hrx9-5wfc: A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-12
Published