CVE Vulnerabilities

CVE-2024-35281

Improper Isolation or Compartmentalization

Published: May 13, 2025 | Modified: Nov 19, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.

Weakness

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Affected Software

NameVendorStart VersionEnd Version
ForticlientFortinet7.0.0 (including)7.2.9 (excluding)
ForticlientFortinet7.4.0 (including)7.4.3 (excluding)
Fortifone_softclientFortinet3.0.0 (including)3.0.16 (including)

Potential Mitigations

References