CVE-2017-7344 Vulnerability Details

  /     /     /  

CVE-2017-7344 Metadata Quick Info

CVE Published: 14/12/2017 | CVE Updated: 25/10/2024 | CVE Year: 2017
Source: fortinet | Vendor: Fortinet, Inc. | Product: FortiClientWindows
Status : PUBLISHED

CVE-2017-7344 Description

A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Windows "security alert" dialog thereby popping up when the "VPN before logon" feature is enabled and an untrusted certificate chain.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Escalation of privilege
Source: Fortinet, Inc.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).