#VU100451 Improper verification of cryptographic signature in FortiClient (macOS) - CVE-2024-40592
Published: November 14, 2024
FortiClient (macOS)
Fortinet, Inc
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to missing verification of cryptographic signature when installing the application. A local user can swap the installer with a malicious package via a race condition during the installation process and escalate privileges on the system.