CVE-2018-9191

Description

A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attackers to execute unauthorized code or commands via the named pipe responsible for Forticlient updates.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.051

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-13368,CVE-2018-9191,CVE-2018-9193,CVE-2019-5585 are affected in Forticlient 6.0.4Windows
CVE-2018-9191NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234