An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Forticlient | Fortinet | 7.0.0 (including) | 7.2.10 (excluding) |
| Forticlient | Fortinet | 7.4.0 (including) | 7.4.4 (excluding) |