CVE-2024-35281

LOW

FortiClientMac <7.4.2 - Code Injection

Title source: llm
STIX 2.1

Description

An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.

References (1)

Core 1
Core References

Scores

CVSS v3 2.5
EPSS 0.0006
EPSS Percentile 17.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-653
Status published
Products (2)
fortinet/forticlient 7.0.0 - 7.2.9
fortinet/fortifone_softclient 3.0.0 - 3.0.16
Published May 13, 2025
Tracked Since Feb 18, 2026