A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
Solution:
The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.
Link | Tags |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-144 | vendor advisory |