PT-2025-47354 · Fortinet · Forticlientwindows

Published

2025-11-18

·

Updated

2025-11-30

·

CVE-2025-47761

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fortinet FortiClientWindows versions 7.2.0 through 7.2.9 Fortinet FortiClientWindows versions 7.4.0 through 7.4.3
Description A flaw exists in Fortinet FortiClientWindows that involves an exposed IOCTL with insufficient access control. This could allow a user with local access to execute code without authorization through the fortips driver. Successful exploitation requires bypassing Windows memory protections like Heap integrity and HSP, and a valid, active VPN IPSec connection is necessary.
Recommendations Update FortiClientWindows to a version later than 7.2.9. Update FortiClientWindows to a version later than 7.4.3.

Fix

LPE

Weakness Enumeration

Related Identifiers

BDU:2025-14867
CVE-2025-47761

Affected Products

Forticlientwindows