VYPR
Medium severity6.3NVD Advisory· Published Jun 1, 2020· Updated Jun 17, 2026

CVE-2020-9291

CVE-2020-9291

Description

An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack.

Affected products

3
  • cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*+ 2 more
    • cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*range: <=6.0.9
    • (no CPE)range: <=6.2.1
    • (no CPE)range: FortiClient for Windows 6.2.1 and earlier and FortiClient for Windows 6.0.9 and earlier

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.