VYPR
Medium severity6.7NVD Advisory· Published Feb 11, 2025· Updated Jun 17, 2026

CVE-2024-40586

CVE-2024-40586

Description

An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*+ 2 more
    • cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*range: >=7.0.3,<7.0.14
    • cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:windows:*:*
    • (no CPE)range: 7.4.0
  • Range: <=7.2.6, <=7.0.13

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.