VYPR
High severity7.4NVD Advisory· Published Nov 2, 2021· Updated Jun 17, 2026

CVE-2021-36183

CVE-2021-36183

Description

An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.

Affected products

3
  • Fortinet/Forticlientllm-fuzzy3 versions
    <=7.0.1, <=6.4.2+ 2 more
    • (no CPE)range: <=7.0.1, <=6.4.2
    • (no CPE)range: FortiClientWindows 7.0.1, 7.0.0, 6.4.2, 6.4.1, 6.4.0
    • cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*range: >=6.4.0,<=6.4.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.