CVE-2025-53950
An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11
Severity
Medium 5.1
CVSS 3.1
Exploited
Not listed
EPSS
0.002
7.8th percentile
Discovered by
Vendor
Vendor advisory field
Published
Oct 16, 2025
Assigned by fortinet
Description
An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1. through 11.1.2 and 11.0.1 and 10.5.1 and 10.4.0, and 10.3.1 may allow an authenticated administrator to collect current user's email information.
Weakness: CWE-359
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiDLP | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiDLP
Credit
Internally discovered and reported by developers of FortiDLP team.
Vendor remediation
Upgrade to FortiDLP version 12.0.0 or above