Lucene search

K
zdiCsaba Fitzl (@theevilbit) of Offensive SecurityZDI-21-693
HistoryJun 17, 2021 - 12:00 a.m.

Fortinet FortiClient Incorrect Permission Assignment Privilege Escalation Vulnerability

2021-06-1700:00:00
Csaba Fitzl (@theevilbit) of Offensive Security
www.zerodayinitiative.com
43

0.0004 Low

EPSS

Percentile

15.9%

This vulnerability allows local attackers to escalate privileges on affected installations of Fortinet FortiClient on Apple macOS. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the FortiClient installer. The issue lies in the lack of proper permissions set on log files created by the installer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.

0.0004 Low

EPSS

Percentile

15.9%