<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Update functionality may lead to privilege escalation vulnerability</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-481</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2023-04-11T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2023-04-11T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2023-04-11T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac may allow a local attacker to escalate their privileges via modifying the installer upon upgrade.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Escalation of privilege
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiClientMac 7.2 all versions are not affectedFortiClientMac version 7.0.0 through 7.0.7FortiClientMac 6.4 all versionsFortiClientMac 6.2 all versionsFortiClientMac 6.0 all versionsFortiClientMac 5.6 all versionsFortiClientMac 5.4 all versionsFortiClientMac 5.2 all versionsFortiClientMac 5.0 all versionsFortiClientMac 4.0 all versions
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiClientMac version 7.0.8 or above.Please upgrade to FortiClientMac version 7.2.0 or above.
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Internally discovered and reported by Eric Hu of Fortinet Software Development team.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiClientMac" Type="Product Name">
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.7">FortiClientMac 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.6">FortiClientMac 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.5">FortiClientMac 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.4">FortiClientMac 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.3">FortiClientMac 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.2">FortiClientMac 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.1">FortiClientMac 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.0">FortiClientMac 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.10">FortiClientMac 6.4.10</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.9">FortiClientMac 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.8">FortiClientMac 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.7">FortiClientMac 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.6">FortiClientMac 6.4.6</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.5">FortiClientMac 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.4">FortiClientMac 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.3">FortiClientMac 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.2">FortiClientMac 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.1">FortiClientMac 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.0">FortiClientMac 6.4.0</FullProductName>
                </Branch>
                <Branch Name="6.2.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.2.9">FortiClientMac 6.2.9</FullProductName>
                </Branch>
                <Branch Name="6.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.2.8">FortiClientMac 6.2.8</FullProductName>
                </Branch>
                <Branch Name="6.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.2.7">FortiClientMac 6.2.7</FullProductName>
                </Branch>
                <Branch Name="6.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.2.6">FortiClientMac 6.2.6</FullProductName>
                </Branch>
                <Branch Name="6.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.2.5">FortiClientMac 6.2.5</FullProductName>
                </Branch>
                <Branch Name="6.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.2.4">FortiClientMac 6.2.4</FullProductName>
                </Branch>
                <Branch Name="6.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.2.3">FortiClientMac 6.2.3</FullProductName>
                </Branch>
                <Branch Name="6.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.2.2">FortiClientMac 6.2.2</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.2.1">FortiClientMac 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.2.0">FortiClientMac 6.2.0</FullProductName>
                </Branch>
                <Branch Name="6.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.0.10">FortiClientMac 6.0.10</FullProductName>
                </Branch>
                <Branch Name="6.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.0.9">FortiClientMac 6.0.9</FullProductName>
                </Branch>
                <Branch Name="6.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.0.8">FortiClientMac 6.0.8</FullProductName>
                </Branch>
                <Branch Name="6.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.0.7">FortiClientMac 6.0.7</FullProductName>
                </Branch>
                <Branch Name="6.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.0.6">FortiClientMac 6.0.6</FullProductName>
                </Branch>
                <Branch Name="6.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.0.5">FortiClientMac 6.0.5</FullProductName>
                </Branch>
                <Branch Name="6.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.0.4">FortiClientMac 6.0.4</FullProductName>
                </Branch>
                <Branch Name="6.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.0.3">FortiClientMac 6.0.3</FullProductName>
                </Branch>
                <Branch Name="6.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.0.2">FortiClientMac 6.0.2</FullProductName>
                </Branch>
                <Branch Name="6.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.0.1">FortiClientMac 6.0.1</FullProductName>
                </Branch>
                <Branch Name="5.6.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.6.6">FortiClientMac 5.6.6</FullProductName>
                </Branch>
                <Branch Name="5.6.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.6.5">FortiClientMac 5.6.5</FullProductName>
                </Branch>
                <Branch Name="5.6.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.6.3">FortiClientMac 5.6.3</FullProductName>
                </Branch>
                <Branch Name="5.6.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.6.1">FortiClientMac 5.6.1</FullProductName>
                </Branch>
                <Branch Name="5.6.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.6.0">FortiClientMac 5.6.0</FullProductName>
                </Branch>
                <Branch Name="5.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.4.4">FortiClientMac 5.4.4</FullProductName>
                </Branch>
                <Branch Name="5.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.4.3">FortiClientMac 5.4.3</FullProductName>
                </Branch>
                <Branch Name="5.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.4.2">FortiClientMac 5.4.2</FullProductName>
                </Branch>
                <Branch Name="5.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.4.1">FortiClientMac 5.4.1</FullProductName>
                </Branch>
                <Branch Name="5.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.4.0">FortiClientMac 5.4.0</FullProductName>
                </Branch>
                <Branch Name="5.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.2.6">FortiClientMac 5.2.6</FullProductName>
                </Branch>
                <Branch Name="5.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.2.5">FortiClientMac 5.2.5</FullProductName>
                </Branch>
                <Branch Name="5.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.2.4">FortiClientMac 5.2.4</FullProductName>
                </Branch>
                <Branch Name="5.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.2.3">FortiClientMac 5.2.3</FullProductName>
                </Branch>
                <Branch Name="5.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.2.2">FortiClientMac 5.2.2</FullProductName>
                </Branch>
                <Branch Name="5.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.2.1">FortiClientMac 5.2.1</FullProductName>
                </Branch>
                <Branch Name="5.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.2.0">FortiClientMac 5.2.0</FullProductName>
                </Branch>
                <Branch Name="5.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.0.10">FortiClientMac 5.0.10</FullProductName>
                </Branch>
                <Branch Name="5.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.0.9">FortiClientMac 5.0.9</FullProductName>
                </Branch>
                <Branch Name="5.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.0.8">FortiClientMac 5.0.8</FullProductName>
                </Branch>
                <Branch Name="5.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.0.7">FortiClientMac 5.0.7</FullProductName>
                </Branch>
                <Branch Name="5.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.0.6">FortiClientMac 5.0.6</FullProductName>
                </Branch>
                <Branch Name="5.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.0.5">FortiClientMac 5.0.5</FullProductName>
                </Branch>
                <Branch Name="5.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.0.4">FortiClientMac 5.0.4</FullProductName>
                </Branch>
                <Branch Name="5.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.0.3">FortiClientMac 5.0.3</FullProductName>
                </Branch>
                <Branch Name="5.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.0.2">FortiClientMac 5.0.2</FullProductName>
                </Branch>
                <Branch Name="5.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.0.1">FortiClientMac 5.0.1</FullProductName>
                </Branch>
                <Branch Name="5.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-5.0.0">FortiClientMac 5.0.0</FullProductName>
                </Branch>
                <Branch Name="4.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-4.0.3">FortiClientMac 4.0.3</FullProductName>
                </Branch>
                <Branch Name="4.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-4.0.2">FortiClientMac 4.0.2</FullProductName>
                </Branch>
                <Branch Name="4.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-4.0.1">FortiClientMac 4.0.1</FullProductName>
                </Branch>
                <Branch Name="4.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-4.0.0">FortiClientMac 4.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Update functionality may lead to privilege escalation vulnerability</Title>
        <cvrf:CVE>CVE-2023-22635</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiClientMac-7.0.7</ProductID>
                <ProductID>FortiClientMac-7.0.6</ProductID>
                <ProductID>FortiClientMac-7.0.5</ProductID>
                <ProductID>FortiClientMac-7.0.4</ProductID>
                <ProductID>FortiClientMac-7.0.3</ProductID>
                <ProductID>FortiClientMac-7.0.2</ProductID>
                <ProductID>FortiClientMac-7.0.1</ProductID>
                <ProductID>FortiClientMac-7.0.0</ProductID>
                <ProductID>FortiClientMac-6.4.10</ProductID>
                <ProductID>FortiClientMac-6.4.9</ProductID>
                <ProductID>FortiClientMac-6.4.8</ProductID>
                <ProductID>FortiClientMac-6.4.7</ProductID>
                <ProductID>FortiClientMac-6.4.6</ProductID>
                <ProductID>FortiClientMac-6.4.5</ProductID>
                <ProductID>FortiClientMac-6.4.4</ProductID>
                <ProductID>FortiClientMac-6.4.3</ProductID>
                <ProductID>FortiClientMac-6.4.2</ProductID>
                <ProductID>FortiClientMac-6.4.1</ProductID>
                <ProductID>FortiClientMac-6.4.0</ProductID>
                <ProductID>FortiClientMac-6.2.9</ProductID>
                <ProductID>FortiClientMac-6.2.8</ProductID>
                <ProductID>FortiClientMac-6.2.7</ProductID>
                <ProductID>FortiClientMac-6.2.6</ProductID>
                <ProductID>FortiClientMac-6.2.5</ProductID>
                <ProductID>FortiClientMac-6.2.4</ProductID>
                <ProductID>FortiClientMac-6.2.3</ProductID>
                <ProductID>FortiClientMac-6.2.2</ProductID>
                <ProductID>FortiClientMac-6.2.1</ProductID>
                <ProductID>FortiClientMac-6.2.0</ProductID>
                <ProductID>FortiClientMac-6.0.10</ProductID>
                <ProductID>FortiClientMac-6.0.9</ProductID>
                <ProductID>FortiClientMac-6.0.8</ProductID>
                <ProductID>FortiClientMac-6.0.7</ProductID>
                <ProductID>FortiClientMac-6.0.6</ProductID>
                <ProductID>FortiClientMac-6.0.5</ProductID>
                <ProductID>FortiClientMac-6.0.4</ProductID>
                <ProductID>FortiClientMac-6.0.3</ProductID>
                <ProductID>FortiClientMac-6.0.2</ProductID>
                <ProductID>FortiClientMac-6.0.1</ProductID>
                <ProductID>FortiClientMac-5.6.6</ProductID>
                <ProductID>FortiClientMac-5.6.5</ProductID>
                <ProductID>FortiClientMac-5.6.3</ProductID>
                <ProductID>FortiClientMac-5.6.1</ProductID>
                <ProductID>FortiClientMac-5.6.0</ProductID>
                <ProductID>FortiClientMac-5.4.4</ProductID>
                <ProductID>FortiClientMac-5.4.3</ProductID>
                <ProductID>FortiClientMac-5.4.2</ProductID>
                <ProductID>FortiClientMac-5.4.1</ProductID>
                <ProductID>FortiClientMac-5.4.0</ProductID>
                <ProductID>FortiClientMac-5.2.6</ProductID>
                <ProductID>FortiClientMac-5.2.5</ProductID>
                <ProductID>FortiClientMac-5.2.4</ProductID>
                <ProductID>FortiClientMac-5.2.3</ProductID>
                <ProductID>FortiClientMac-5.2.2</ProductID>
                <ProductID>FortiClientMac-5.2.1</ProductID>
                <ProductID>FortiClientMac-5.2.0</ProductID>
                <ProductID>FortiClientMac-5.0.10</ProductID>
                <ProductID>FortiClientMac-5.0.9</ProductID>
                <ProductID>FortiClientMac-5.0.8</ProductID>
                <ProductID>FortiClientMac-5.0.7</ProductID>
                <ProductID>FortiClientMac-5.0.6</ProductID>
                <ProductID>FortiClientMac-5.0.5</ProductID>
                <ProductID>FortiClientMac-5.0.4</ProductID>
                <ProductID>FortiClientMac-5.0.3</ProductID>
                <ProductID>FortiClientMac-5.0.2</ProductID>
                <ProductID>FortiClientMac-5.0.1</ProductID>
                <ProductID>FortiClientMac-5.0.0</ProductID>
                <ProductID>FortiClientMac-4.0.3</ProductID>
                <ProductID>FortiClientMac-4.0.2</ProductID>
                <ProductID>FortiClientMac-4.0.1</ProductID>
                <ProductID>FortiClientMac-4.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>6.9</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L/E:P/RL:X/RC:X</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-481</URL>
                <Description>Update functionality may lead to privilege escalation vulnerability</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>