PT-2025-41961 · Fortinet · Forticlient
Published
2025-10-14
·
Updated
2025-10-15
·
CVE-2025-57716
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiClient versions 7.0 through 7.2.11 and 7.4.0 through 7.4.3
Description
An uncontrolled search path element issue exists in FortiClient on Windows. A local, low-privileged user could potentially perform a DLL hijacking attack by placing a malicious DLL in the FortiClient Online Installer installation folder.
Recommendations
Update FortiClient to a version later than 7.4.3
Update FortiClient to a version later than 7.2.11
Update FortiClient to a version later than 7.0
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forticlient