CVE Vulnerabilities

CVE-2024-35281

Improper Isolation or Compartmentalization

Published: May 13, 2025 | Modified: Nov 19, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.

Weakness

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Affected Software

Name Vendor Start Version End Version
Forticlient Fortinet 7.0.0 (including) 7.2.9 (excluding)
Forticlient Fortinet 7.4.0 (including) 7.4.3 (excluding)
Fortifone_softclient Fortinet 3.0.0 (including) 3.0.16 (including)

Potential Mitigations

References