CVE-2017-7344

HIGH

Fortinet FortiClient <5.4.3, <5.6.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Windows "security alert" dialog thereby popping up when the "VPN before logon" feature is enabled and an untrusted certificate chain.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102176
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-17-070

Scores

CVSS v3 8.1
EPSS 0.0127
EPSS Percentile 79.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (3)
fortinet/forticlient 5.6.0
fortinet/forticlient < 5.4.3
Fortinet, Inc./FortiClientWindows 5.6.0, 5.4.3, 5.4.2, 5.4.1, 5.4.0
Published Dec 14, 2017
Tracked Since Feb 18, 2026