PT-2024-13254 · Fortinet · Forticlientmac
Published
2023-10-09
·
Updated
2025-07-15
·
CVE-2023-45588
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
FortiClientMac versions 7.2.3 and below
FortiClientMac version 7.0.10 and below installer
Description:
The issue allows a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process. This is due to an external control of file name or path vulnerability.
Recommendations:
For FortiClientMac versions 7.2.3 and below, update to a version above 7.2.3 to resolve the issue.
For FortiClientMac version 7.0.10 and below installer, update the installer to a version above 7.0.10 to mitigate the risk.
As a temporary workaround, consider restricting write access to the /tmp directory to prevent malicious configuration files from being written.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forticlientmac