Fortinet patches VPN app flaw that could give rogue users, malware a privilege boost
ID: b2d98d9b-9bfe-5123-9b6a-881a4f2adc94
STIX ID: report--b2d98d9b-9bfe-5123-9b6a-881a4f2adc94
Feed Name: The Register (Security)
Threat Score
A high-severity FortiClient VPN vulnerability (CVE-2024-47574, CVSS 7.8) and a related registry-privilege flaw (CVE-2024-50564) were disclosed and patched in FortiClient 7.4.1 and other fixed releases; exploitation can lead to local privilege escalation, code execution (via process hollowing), deletion of logs, and modification of HKLM registry values, but neither issue has been observed exploited in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
