CVE-2025-57741

An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local attacker to run arbitra

Severity
High 7
CVSS 3.1
Exploited
Not listed
EPSS
0.001
2.8th percentile
Discovered by
Third party
Vendor advisory field
Published
Oct 14, 2025
Assigned by fortinet

Description

An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local attacker to run arbitrary code or commands via LaunchDaemon hijacking.

Weakness: CWE-732

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiClientMac

Credit

Fortinet is pleased to thank Isaac Ordonez from Mann Consulting for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiClientMac version 7.4.4 or above Upgrade to FortiClientMac version 7.2.12 or above

Something wrong here?