mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
20 lines
942 B
Markdown
20 lines
942 B
Markdown
### [CVE-2024-40586](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40586)
|
||

|
||

|
||

|
||

|
||

|
||
|
||
### Description
|
||
|
||
An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
No PoCs from references.
|
||
|
||
#### Github
|
||
- https://github.com/Hagrid29/CVE-2024-40586-Windows-Coerced-Authentication-in-FortiClient
|
||
|