Path Traversal Vulnerability in Fortinet FortiDLP Agent for MacOS
CVE-2025-54658

7.2HIGH

Key Information:

Vendor

Fortinet

Status
Vendor
CVE Published:
16 October 2025

What is CVE-2025-54658?

An improper limitation of a pathname to a restricted directory vulnerability exists in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS. This flaw may allow an authenticated attacker to escalate their privileges to Root level by sending specially crafted requests to a local listening port. The affected versions range from 10.3.1 through 11.5.1, making multiple releases susceptible to exploitation. It is crucial for users to be aware of this vulnerability and implement timely updates.

Affected Version(s)

FortiDLP 11.5.1

FortiDLP 11.4.2 <= 11.4.6

FortiDLP 11.3.2 <= 11.3.4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54658 : Path Traversal Vulnerability in Fortinet FortiDLP Agent for MacOS