Medium severity5.5NVD Advisory· Published Oct 16, 2025· Updated Jun 17, 2026
CVE-2025-53950
CVE-2025-53950
Description
An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1. through 11.1.2 and 11.0.1 and 10.5.1 and 10.4.0, and 10.3.1 may allow an authenticated administrator to collect current user's email information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:fortinet:fortidlp_agent:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortidlp_agent:*:*:*:*:*:*:*:*range: >=10.3.1,<=11.5.1
- (no CPE)range: 11.5.1, 11.4.2-11.4.6, 11.3.2-11.3.4, 11.2.0-11.2.3, 11.1.1-11.1.2, 11.0.1, 10.5.1, 10.4.0, 10.3.1
- Range: 11.5.1, 11.4.2-11.4.6, 11.3.2-11.3.4, 11.2.0-11.2.3, 11.1.1-11.1.2, 11.0.1, 10.5.1, 10.4.0, 10.3.1
Patches
Vulnerability mechanics
References
1- fortiguard.fortinet.com/psirt/FG-IR-25-639nvdVendor Advisory
News mentions
0No linked articles in our index yet.