CVE-2025-57741
BaseFortify
Publication date: 2025-10-14
Last updated on: 2025-10-15
Assigner: Fortinet, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | forticlient | From 7.4.0 (inc) to 7.4.3 (inc) |
| fortinet | forticlient | From 7.4.0 (inc) to 7.4.3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Incorrect Permission Assignment for a Critical Resource in FortiClientMac versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, and all versions of 7.0. It may allow a local attacker to run arbitrary code or commands by hijacking a LaunchDaemon, which is a system process that manages background services.
How can this vulnerability impact me? :
The vulnerability can allow a local attacker to execute arbitrary code or commands on the affected system, potentially leading to full compromise of confidentiality, integrity, and availability of the system.