FortiClient (Windows) - Privilege escalation vulnerability


An improper authorization vulnerability [CWE-285] in FortiClient for Windows may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates. 

Affected Products

FortiClientWindows version 6.4.2 and below.
ForticlientWindows version 7.0.1 and below.


Please upgrade FortiClientWindows to version 6.4.3 or above.

Please upgarde FortiClientWindows to version 7.0.2 or above.




Fortinet is pleased to thank Dimitri Gasser, Nicola Stauffer and Daniel Hulliger for reporting this vulnerability under responsible disclosure.