{"id":"CVE-2025-46774","title":"An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiCl…","summary":"An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiCl…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-347"],"vendor":"fortinet","product":"forticlient","affected":["forticlient >= 7.0.0, < 7.2.10","forticlient >= 7.4.0, < 7.4.4"],"patched":["forticlient 7.4.4"],"published":"2025-10-14","updated":"2026-10-08","sourceUpdated":"2026-10-08T12:10:00.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-46774","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-25-126","label":"psirt@fortinet.com"}],"tags":["nvd"],"epss":0.00082,"epssPercentile":0.00191,"ingestedAt":"2026-10-08T11:31:27.388Z","slug":"CVE-2025-46774","body":"## Overview\n\nAn Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables.\n\n## Affected\n\n- `forticlient >= 7.0.0, < 7.2.10`\n- `forticlient >= 7.4.0, < 7.4.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `forticlient 7.4.4`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}