ZeroHour

CVE-2024-35281

CVSS 3.1
7.8 high
EPSS
<1%p3
Published
()
Modified
Description

An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.

Vendors
fortinet
Products
forticlient, fortifone softclient
Weakness
CWE-653
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.