PSIRT Advisories
FortiClient (Windows) - Privilege Escalation via directory traversal attack
Summary
A relative path traversal vulnerability [CWE-23] in FortiClient for Windows may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for FortiESNAC service.
Affected Products
FortiClientWindows version 7.0.0 through 7.0.2FortiClientWindows version 6.4.0 through 6.4.6
FortiClientWindows version 6.2.0 through 6.2.9
Solutions
Please upgrade to FortiClientWindows version 7.0.3 or abovePlease upgrade to FortiClientWindows version 6.4.7 or above