CVE-2025-53950

An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1. through 11.1.2 and 11.0.1 and 10.5.1 and 10.4.0, and 10.3.1 may allow an authenticated administrator to collect current user's email information.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:fortinet:fortidlp_agent:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

16 Oct 2025, 17:54

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:fortidlp_agent:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://fortiguard.fortinet.com/psirt/FG-IR-25-639 - () https://fortiguard.fortinet.com/psirt/FG-IR-25-639 - Vendor Advisory
First Time Apple
Microsoft
Microsoft windows
Apple macos
Fortinet
Fortinet fortidlp Agent

16 Oct 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-16 14:15

Updated : 2025-10-16 17:54


NVD link : CVE-2025-53950

Mitre link : CVE-2025-53950

CVE.ORG link : CVE-2025-53950


JSON object : View

Products Affected

apple

  • macos

fortinet

  • fortidlp_agent

microsoft

  • windows
CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor