PT-2025-41954 · Fortinet · Forticlient

Published

2025-10-14

·

Updated

2025-10-22

·

CVE-2025-46774

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiClient versions 7.0 through 7.2.9 FortiClient versions 7.4.2 and below
Description An issue exists in FortiClient for macOS where improper verification of cryptographic signatures may allow a local user to escalate privileges through FortiClient related executables. The flaw resides in the cryptographic signature verification process of FortiClient executables, enabling a local attacker to gain elevated access to the system.
Recommendations Update FortiClient to a version later than 7.2.9. Update FortiClient to a version later than 7.4.2.

Fix

LPE

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

BDU:2026-05219
CVE-2025-46774

Affected Products

Forticlient