CVE-2024-35281: High severity Fortinet FortiClientMac vulnerability
An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35281?
CVE-2024-35281 has been rated as a critical severity vulnerability.
How do I fix CVE-2024-35281?
To remediate CVE-2024-35281, upgrade FortiClientMac to version 7.4.3 or above, or FortiVoiceUCDesktop to a version higher than 3.0.
What software is affected by CVE-2024-35281?
CVE-2024-35281 affects FortiClientMac versions 7.4.2 and below, 7.2.8 and below, 7.0 all versions, and FortiVoiceUCDesktop 3.0 all versions.
Can an attacker exploit CVE-2024-35281 without authentication?
No, CVE-2024-35281 requires an authenticated attacker to exploit the vulnerability.
What type of vulnerability is CVE-2024-35281?
CVE-2024-35281 is classified as an improper isolation or compartmentalization vulnerability.