FortiClient and EMS
CVE-2023-45588: External control of file name or path in FortiClientMac
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| FortiClientMac 7.2.0 to 7.2.3 | 7.2.4 or later |
| FortiClientMac 7.0.6 to 7.0.10 | 7.0.11 or later |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.