VYPR
High severity7.4NVD Advisory· Published Nov 2, 2021· Updated Jun 17, 2026

CVE-2021-36183

CVE-2021-36183

Description

An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.

Affected products

2
  • Fortinet/Forticlientllm-fuzzy2 versions
    <=7.0.1, <=6.4.2+ 1 more
    • (no CPE)range: <=7.0.1, <=6.4.2
    • (no CPE)range: FortiClientWindows 7.0.1, 7.0.0, 6.4.2, 6.4.1, 6.4.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.