An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.
2024-04-10T13:51:38.607
2025-01-23T15:58:57.733
Analyzed
CVSSv3.1: 8.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | forticlient | < 7.0.11 | Yes |
Application | fortinet | forticlient | < 7.2.4 | Yes |