CVE Vulnerabilities

CVE-2025-46774

Improper Verification of Cryptographic Signature

Published: Oct 14, 2025 | Modified: Oct 22, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Forticlient Fortinet 7.0.0 (including) 7.2.10 (excluding)
Forticlient Fortinet 7.4.0 (including) 7.4.4 (excluding)

References