CVE-2023-22635: High severity fortinet forticlient vulnerability
A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions, 5.6 all versions, 5.4 all versions, 5.2 all versions, 5.0 all versions and 4.0 all versions may allow a local attacker to escalate their privileges via modifying the installer upon upgrade.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-22635.
What is the severity of CVE-2023-22635?
The severity of CVE-2023-22635 is high with a severity value of 7.8.
Which software versions are affected by this vulnerability?
The FortiClientMac versions 7.0.0 through 7.0.7, 6.4.x, 6.2.x, 6.0.x, 5.6.x, 5.4.x, 5.2.x, 5.0.x, and 4.0.x are affected.
What is the CWE ID associated with CVE-2023-22635?
The CWE ID associated with CVE-2023-22635 is CWE-494.
How can a local attacker exploit this vulnerability?
A local attacker can exploit this vulnerability by downloading code without integrity check, allowing them to escalate privileges.