High severity7.4NVD Advisory· Published Nov 2, 2021· Updated Jun 17, 2026
CVE-2021-36183
CVE-2021-36183
Description
An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.
Affected products
2<=7.0.1, <=6.4.2+ 1 more
- (no CPE)range: <=7.0.1, <=6.4.2
- (no CPE)range: FortiClientWindows 7.0.1, 7.0.0, 6.4.2, 6.4.1, 6.4.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-20-079nvdVendor Advisory
News mentions
0No linked articles in our index yet.