CVE-2019-15711

HIGH

FortiClient < 6.2.1 - Privilege Escalation via ExportLogs IPC Request Injection

Title source: llm
STIX 2.1

Description

A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root privilege via injecting specially crafted "ExportLogs" type IPC client requests to the fctsched process.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/psirt/FG-IR-19-238
Exploit, Third Party Advisory x_refsource_misc
https://danishcyberdefence.dk/blog/forticlient_linux

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 31.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (1)
fortinet/forticlient < 6.2.1
Published Feb 06, 2020
Tracked Since Feb 18, 2026