An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1. through 11.1.2 and 11.0.1 and 10.5.1 and 10.4.0, and 10.3.1 may allow an authenticated administrator to collect current user's email information.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-25-639 |
![]() ![]() |
History
Thu, 16 Oct 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apple
Apple macos Fortinet fortidlp Agent Microsoft Microsoft windows |
|
CPEs | cpe:2.3:a:fortinet:fortidlp_agent:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Apple
Apple macos Fortinet fortidlp Agent Microsoft Microsoft windows |
Thu, 16 Oct 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 16 Oct 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1. through 11.1.2 and 11.0.1 and 10.5.1 and 10.4.0, and 10.3.1 may allow an authenticated administrator to collect current user's email information. | |
First Time appeared |
Fortinet
Fortinet fortidlp |
|
Weaknesses | CWE-359 | |
CPEs | cpe:2.3:a:fortinet:fortidlp:10.3.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:10.4.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:10.5.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.0.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.1.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.1.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.2.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.2.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.3.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.3.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.3.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.4.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.4.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.4.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.4.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.4.6:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortidlp:11.5.1:*:*:*:*:*:*:* |
|
Vendors & Products |
Fortinet
Fortinet fortidlp |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-10-16T14:22:55.551Z
Reserved: 2025-07-15T09:52:08.702Z
Link: CVE-2025-53950

Updated: 2025-10-16T14:22:52.436Z

Status : Analyzed
Published: 2025-10-16T14:15:35.897
Modified: 2025-10-16T17:54:14.000
Link: CVE-2025-53950

No data.

No data.