---
cve: "CVE-2025-53950"
severity: "MEDIUM"
cvss: 5.1
epss: "0.2%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2025-10-16 14:15:35"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T16:09:10+02:00"
---

# CVE-2025-53950

> 5.1 MEDIUM

## Beschreibung

An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1. through 11.1.2 and 11.0.1 and 10.5.1 and 10.4.0, and 10.3.1 may allow an authenticated administrator to collect current user's email information.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N/E:F/RL:O/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Erforderlich | good |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-359** — Exposure of Private Personal Information to an Unauthorized Actor
  The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

## Angriffsmuster (CAPEC)

- [CAPEC-464 — Evercookie](https://capec.mitre.org/data/definitions/464.html) _(Severity: Medium)_
- [CAPEC-467 — Cross Site Identification](https://capec.mitre.org/data/definitions/467.html) _(Severity: Low)_
- [CAPEC-498 — Probe iOS Screenshots](https://capec.mitre.org/data/definitions/498.html)
- [CAPEC-508 — Shoulder Surfing](https://capec.mitre.org/data/definitions/508.html) _(Severity: High)_

## ATT&CK-Techniken

- [T1606.001 — Forge Web Credentials: Web Cookies](https://attack.mitre.org/techniques/T1606/001/)

## Referenzen

- <https://fortiguard.fortinet.com/psirt/FG-IR-25-639>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-53950) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
