CVE-2020-15934: Fortinet FortiClient
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine.
Affected products
- Fortinet FortiClient: from 6.0.0, before 6.2.8 (fixed in 6.2.8); version 6.4.0 only
Published 2024-12-19. Last modified 2026-06-17.