CVE-2024-40592: Race Condition
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40592?
CVE-2024-40592 has been assigned a medium severity rating due to its potential for exploitation by local authenticated attackers.
How do I fix CVE-2024-40592?
To fix CVE-2024-40592, update FortiClient to version 7.4.1 or later, or to any version above 7.2.5, 7.0.11, or 6.4.11.
Who is affected by CVE-2024-40592?
CVE-2024-40592 affects users of FortiClient on MacOS versions 6.4.10 and below, 7.0.10 and below, 7.2.4 and below, and 7.4.0.
What type of vulnerability is CVE-2024-40592?
CVE-2024-40592 is an improper verification of cryptographic signature vulnerability classified under CWE-347.
Can CVE-2024-40592 be exploited remotely?
No, CVE-2024-40592 can only be exploited by local authenticated attackers.