CVE-2024-40586
published 2025-02-11CVE-2024-40586: An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.24%
15.5th percentile
An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | — | — |
| fortinet | forticlient | >= 7.0.3 < 7.0.14 | 7.0.14 |
| fortinet | forticlient | >= 7.2.0 < 7.2.7 | 7.2.7 |
| fortinet | forticlientwindows | — | — |
| fortinet | forticlientwindows | 7.0.3 – 7.0.13 | — |
| fortinet | forticlientwindows | 7.2.0 – 7.2.6 | — |
| fortinet | fortisslvpnd | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, versio...
vendor_fortinet·2025-02-11·CVSS 6.7
CVE-2024-40586 [MEDIUM] CWE-284 An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, versio...
FG-IR-23-279: An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, versio...
An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.
CVEs: CVE-2024-40586
CWEs: CWE-284
CVSS: 6.7 (medium)
Affected products: FortiClient, FortiSSLVPNd
GHSA
GHSA-89gg-gc7x-gwhp: An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7
ghsa_unreviewed·2025-02-11
CVE-2024-40586 [MEDIUM] CWE-284 GHSA-89gg-gc7x-gwhp: An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7
An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.
Suricata
ET WEB_CLIENT Adobe Authplay.dll NewClass Memory Corruption Attempt
suricata·2011-07-15
CVE-2010-1297 ET WEB_CLIENT Adobe Authplay.dll NewClass Memory Corruption Attempt
ET WEB_CLIENT Adobe Authplay.dll NewClass Memory Corruption Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Adobe Authplay.dll NewClass Memory Corruption Attempt"; flow:established,to_client; flowbits:isset,ET.flash.pdf; file.data; content:"|D2 60 38 40 BA 03 14 0E|"; reference:url,www.exploit-db.com/adobe-acrobat-newclass-invalid-pointer-vulnerability/; reference:bid,40586; reference:cve,2010-1297; classtype:attempted-user; sid:2013281; rev:5; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2011_07_15, cve CVE_2010_1297, deployment Perimeter, confidence Medium, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_09;)
No public exploits indexed.
No writeups or analysis indexed.
2025-02-11
Published