CVE-2024-35281

An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desk

Severity
Low 2.3
CVSS 3.1
Exploited
Not listed
EPSS
0.001
2.6th percentile
Discovered by
Not disclosed
Published
May 13, 2025
Assigned by fortinet

Description

An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.

Weakness: CWE-653

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported affected versions (2)
  • Fortinet · FortiClientMac
  • Fortinet · FortiVoiceUCDesktop

Vendor remediation

Please upgrade to FortiClientMac version 7.4.3 or above Please upgrade to FortiClientMac version 7.2.9 or above Please upgrade to FortiVoiceUCDesktop version 7.0.0 or above