CVE-2024-35281

An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desk

Severity
Low 2.3
CVSS 3.1
Exploited
Not listed
EPSS
0.001
3.6th percentile
Discovered by
Third party
Vendor advisory field
Published
May 13, 2025
Assigned by fortinet

Description

An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.

Weakness: CWE-653

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Fortinet FortiVoice Other Products cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiClientMac
  • Fortinet · FortiVoiceUCDesktop

Credit

Fortinet is pleased to thank YoKo Kho and Fahad Alamri from HakTrak Cybersecurity Squad, Mykola Grymalyuk, Roberto "espret0" Soares from Hakai Security, Kahabordee Pinjai and Kusol Watchara-ApanukornCompany from Sec Strike Research team and Nissana Sirijirakal from SnoopBees Co., Ltd. for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiClientMac version 7.4.3 or above Please upgrade to FortiClientMac version 7.2.9 or above Please upgrade to FortiVoiceUCDesktop version 7.0.0 or above

Something wrong here?