Medium severity6.3NVD Advisory· Published Jun 1, 2020· Updated Jun 17, 2026
CVE-2020-9291
CVE-2020-9291
Description
An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack.
Affected products
3cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*+ 2 more
- cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*range: <=6.0.9
- (no CPE)range: <=6.2.1
- (no CPE)range: FortiClient for Windows 6.2.1 and earlier and FortiClient for Windows 6.0.9 and earlier
Patches
Vulnerability mechanics
References
2- www.fortiguard.com/psirt/FG-IR-20-040nvdVendor Advisory
- fortiguard.com/psirt/FG-IR-20-040nvdBroken Link
News mentions
0No linked articles in our index yet.