CVE-2025-57741
An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local attacker to run arbitra
Severity
High 7
CVSS 3.1
Exploited
Not listed
EPSS
0.001
2.8th percentile
Discovered by
Third party
Vendor advisory field
Published
Oct 14, 2025
Assigned by fortinet
Description
An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local attacker to run arbitrary code or commands via LaunchDaemon hijacking.
Weakness: CWE-732
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiClientMac
Credit
Fortinet is pleased to thank Isaac Ordonez from Mann Consulting for reporting this vulnerability under responsible disclosure.
Vendor remediation
Upgrade to FortiClientMac version 7.4.4 or above Upgrade to FortiClientMac version 7.2.12 or above