2025-09-29 16:08:36 +00:00
### [CVE-2024-40586](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40586)

2025-09-29 21:09:30 +02:00




2025-09-29 16:08:36 +00:00
### Description
An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/Hagrid29/CVE-2024-40586-Windows-Coerced-Authentication-in-FortiClient