Fortinet FortiDLP Agent Outlookproxy Plugin Privacy Violation Vulnerability
Vulnerability
A privacy violation vulnerability has been identified in the Fortinet FortiDLP Agent's Outlookproxy plugin, affecting both MacOS and Windows versions 11.5.1, 11.4.2 through 11.4.6, 11.3.2 through 11.3.4, 11.2.0 through 11.2.3, 11.1.1 through 11.1.2, 11.0.1, 10.5.1, 10.4.0, and 10.3.1. This vulnerability allows an authenticated administrator to access current users' email information.
Impact
Exploitation of this vulnerability could lead to unauthorized collection of private email information from users.
Remediation
Users are advised to migrate to a fixed release. Fortinet provides a CVRF and CSAF document for this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
