Back

HIGH

An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious website

Published Oct 14, 2025

Description

An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious website.

Affected products

Remediation

Vendor solution

Upgrade to FortiClientMac version 7.4.4 or above Upgrade to FortiClientMac version 7.2.9 or above

Weaknesses (1)

References (2)

Change history (3)
  1. CISA ADP
    • SSVC technical impact

      changed from total to partial

  2. CISA ADP
    • SSVC technical impact

      changed from partial to total

  3. CISA ADP
    • SSVC technical impact

      changed from total to partial

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fortinet
Published Oct 14, 2025
Updated Feb 26, 2026
Reserved Mar 28, 2025
CISA Vulnrichment
Updated Oct 14, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner fortinet
Published Oct 14, 2025
Updated Feb 26, 2026
Exploited since n/a
EUVD-2025-34232