{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-10T16:58:29.309","vulnerabilities":[{"cve":{"id":"CVE-2024-40586","sourceIdentifier":"psirt@fortinet.com","published":"2025-02-11T17:15:22.683","lastModified":"2026-06-17T07:46:07.903","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe."},{"lang":"es","value":"Una vulnerabilidad de control de acceso inadecuado [CWE-284] en FortiClient versión 7.4.0, versión 7.2.6 y anteriores, versión 7.0.13 y anteriores para Windows puede permitir que un usuario local aumente sus privilegios a través de la tubería de servicio FortiSSLVPNd."}],"affected":[{"source":"psirt@fortinet.com","affectedData":[{"vendor":"Fortinet","product":"FortiClientWindows","defaultStatus":"unaffected","versions":[{"version":"7.4.0","status":"affected"},{"version":"7.2.0","lessThanOrEqual":"7.2.6","versionType":"semver","status":"affected"},{"version":"7.0.3","lessThanOrEqual":"7.0.13","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@fortinet.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-11T16:35:40.693018Z","id":"CVE-2024-40586","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@fortinet.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*","versionStartIncluding":"7.0.3","versionEndExcluding":"7.0.14","matchCriteriaId":"0AFFD932-83AE-4FB3-9949-AE2ADD8B87A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*","versionStartIncluding":"7.2.0","versionEndExcluding":"7.2.7","matchCriteriaId":"D0671451-618C-435A-8E35-49E155CEAD78"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:windows:*:*","matchCriteriaId":"6B512696-8596-4458-ADC9-24DD3C6C377B"}]}]}],"references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-23-279","source":"psirt@fortinet.com","tags":["Vendor Advisory"]}]}}]}