High severity7.8NVD Advisory· Published Jul 18, 2022· Updated Jun 17, 2026
CVE-2021-41031
CVE-2021-41031
Description
A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for FortiESNAC service.
Affected products
3FortiClientWindows 7.0.2, 7.0.1, 7.0.0, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.9, 6.2.8, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0+ 2 more
- (no CPE)range: FortiClientWindows 7.0.2, 7.0.1, 7.0.0, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.9, 6.2.8, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0
- cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*range: >=6.2.0,<=6.2.9
- (no CPE)range: <=7.0.2, <=6.4.6, <=6.2.9
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-21-190nvdBroken LinkPatchVendor Advisory
News mentions
0No linked articles in our index yet.