VYPR
Low severity3.2NVD Advisory· Published Nov 2, 2021· Updated Jun 17, 2026

CVE-2021-42754

CVE-2021-42754

Description

An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file.

Affected products

4
  • cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:*+ 2 more
    • cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:*range: >=6.4.0,<=6.4.5
    • cpe:2.3:a:fortinet:forticlient:7.0.0:*:*:*:*:macos:*:*
    • (no CPE)range: FortiClientMac 7.0.0, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0
  • Range: <=7.0.0, <=6.4.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.