Improper access control to FortiSslvpnNamedPipe

Summary

An Improper Access Control vulnerability [CWE-284] in FortiClient Windows may allow a local user to escalate their privileges via FortiSSLVPNd service pipe.

Version Affected Solution
FortiClientWindows 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiClientWindows 7.2 7.2.0 through 7.2.6 Upgrade to 7.2.7 or above
FortiClientWindows 7.0 7.0.3 through 7.0.13 Upgrade to 7.0.14 or above

Acknowledgement

Fortinet is pleased to thank Erwin Chan for reporting this vulnerability under responsible disclosure.

Timeline

2025-02-11: Initial publication