CVE-2025-31365: Code Injection
An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious website.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31365?
CVE-2025-31365 has been rated as critical due to its potential for arbitrary code execution.
How do I fix CVE-2025-31365?
To mitigate CVE-2025-31365, upgrade FortiClient to the latest version beyond 7.4.3 or 7.2.8.
Who can exploit CVE-2025-31365?
CVE-2025-31365 can be exploited by unauthenticated attackers through social engineering techniques.
What versions of FortiClient are affected by CVE-2025-31365?
CVE-2025-31365 affects FortiClient versions 7.4.0 through 7.4.3 and 7.2.1 through 7.2.8.
What is the impact of CVE-2025-31365?
The impact of CVE-2025-31365 includes the ability for attackers to execute arbitrary code on the victim's machine.