CVE-2021-42754: Code Injection
Published Nov 2, 2021
·Updated
An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file.
Affected Software
2 affected components
Fortinet Forticlient Macos>=6.4.0<=6.4.5
Fortinet Forticlient Macos=7.0.0
Event History
Nov 2, 2021
CVE Published
via MITRE·06:56 PM
Data Sourced
via MITRE·06:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-42754.
2
What is the severity of CVE-2021-42754?
CVE-2021-42754 has a severity level of medium (5).
3
Which versions of FortiClientMacOS are affected by CVE-2021-42754?
FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below are affected by CVE-2021-42754.
4
How can an attacker exploit CVE-2021-42754?
An authenticated attacker can exploit CVE-2021-42754 by hijacking the MacOS camera without user permission using a malicious dylib file.
5
Is there a link for more information about CVE-2021-42754?
Yes, you can find more information about CVE-2021-42754 at the following link: [FortiGuard Advisory FG-IR-21-079](https://fortiguard.com/advisory/FG-IR-21-079).