Privilege escalation via lua auto patch function

Summary

A privilege context switching error vulnerability [CWE-270] in FortiClient Windows may allow an authenticated user to escalate their privileges via lua auto patch scripts.

Version Affected Solution
FortiClientWindows 7.4 Not affected Not Applicable
FortiClientWindows 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiClientWindows 7.0 7.0.0 through 7.0.12 Upgrade to 7.0.13 or above
FortiClientWindows 6.4 6.4.0 through 6.4.10 Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Mengyao Zhang of Fortinet Development team.

Timeline

2024-11-12: Initial publication