CVE-2025-46774: High severity Fortinet FortiClient vulnerability
Published Oct 14, 2025
·Updated
An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables.
Affected Software
3 affected components
Fortinet FortiClient<=7.4.2, <=7.2.9, >=7.0
Fortinet Forticlient Macos>=7.0.0<7.2.10
Fortinet Forticlient Macos>=7.4.0<7.4.4
Remediation
Information
Upgrade to FortiClientMac version 7.4.4 or above
Upgrade to FortiClientMac version 7.2.10 or above
Event History
Oct 14, 2025
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-46774?
CVE-2025-46774 has a high severity rating due to its potential to allow local privilege escalation.
2
How do I fix CVE-2025-46774?
To fix CVE-2025-46774, upgrade FortiClient to version 7.4.3 or higher, or 7.2.10 or higher.
3
What systems are affected by CVE-2025-46774?
CVE-2025-46774 affects FortiClient versions 7.4.2 and below, 7.2.9 and below, and all versions of 7.0.
4
What type of vulnerability is CVE-2025-46774?
CVE-2025-46774 is classified as an Improper Verification of Cryptographic Signature vulnerability.
5
Can CVE-2025-46774 be exploited remotely?
CVE-2025-46774 requires local user access to exploit, making remote exploitation unlikely.