Impact
A flaw that allows an attacker to bypass standard ownership checks within Fortinet FortiClientWindows could enable unauthorized access to protected resources. The vulnerability is classified as an access control weakness, permitting an authenticated or unauthenticated user to perform actions or access data that should be restricted. Because the description indicates improper access control, the potential consequences include data exposure, escalation of privileges, or compromise of system integrity for the affected client installations.
Affected Systems
The vulnerability impacts Fortinet FortiClientWindows version 7.4.0 through 7.4.7 and all releases of the 7.2.x branch, including 7.2.0‑7.2.15. Users running these versions on Windows environments are at risk unless they upgrade or apply a patch.
Risk and Exploitability
The CVSS score of 4.7 signals a moderate risk level, yet the absence of an EPSS score means the likelihood of exploitation is currently unknown. Fortinet has not listed the issue in the CISA KEV catalog, suggesting that no widespread exploitation has been documented. The address vectors are not publicly disclosed; it is inferred that the vulnerability may be triggered through local or remote access mechanisms that involve unverified ownership verification, but specific attack conditions remain unspecified.
OpenCVE Enrichment