An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-025 |
|
History
Wed, 19 Nov 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet forticlient Fortinet fortifone Softclient |
|
| CPEs | cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:* cpe:2.3:a:fortinet:fortifone_softclient:*:*:*:*:*:desktop:*:* |
|
| Vendors & Products |
Fortinet
Fortinet forticlient Fortinet fortifone Softclient |
Tue, 13 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables. | |
| Weaknesses | CWE-653 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published: 2025-05-13T14:46:42.574Z
Updated: 2025-05-13T15:17:58.536Z
Reserved: 2024-05-14T21:15:19.190Z
Link: CVE-2024-35281
Updated: 2025-05-13T15:17:56.064Z
Status : Analyzed
Published: 2025-05-13T15:15:52.060
Modified: 2025-11-19T13:35:35.710
Link: CVE-2024-35281
No data.