An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables.
Advisories

No advisories yet.

Fixes

Solution

Upgrade to FortiClientMac version 7.4.4 or above Upgrade to FortiClientMac version 7.2.10 or above


Workaround

No workaround given by the vendor.

History

Wed, 22 Oct 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet forticlient
CPEs cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:*
Vendors & Products Fortinet forticlient

Mon, 20 Oct 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Fortinet
Fortinet forticlientmac
Vendors & Products Apple
Apple macos
Fortinet
Fortinet forticlientmac

Tue, 14 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Oct 2025 15:45:00 +0000

Type Values Removed Values Added
Description An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables.
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2025-10-16T03:56:19.702Z

Reserved: 2025-04-29T08:42:13.449Z

Link: CVE-2025-46774

cve-icon Vulnrichment

Updated: 2025-10-14T16:36:03.775Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-14T16:15:38.500

Modified: 2025-10-22T16:47:22.450

Link: CVE-2025-46774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-20T15:49:33Z