Fortinet FortiDLP Agent Outlookproxy Plugin Privacy Violation Vulnerability

Vulnerability

A privacy violation vulnerability has been identified in the Fortinet FortiDLP Agent's Outlookproxy plugin, affecting both MacOS and Windows versions 11.5.1, 11.4.2 through 11.4.6, 11.3.2 through 11.3.4, 11.2.0 through 11.2.3, 11.1.1 through 11.1.2, 11.0.1, 10.5.1, 10.4.0, and 10.3.1. This vulnerability allows an authenticated administrator to access current users' email information.

Impact

Exploitation of this vulnerability could lead to unauthorized collection of private email information from users.

Remediation

Users are advised to migrate to a fixed release. Fortinet provides a CVRF and CSAF document for this vulnerability.

Added: Oct 16, 2025, 2:31 PM
Updated: Oct 16, 2025, 3:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
2.8
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.