- Description
- An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips driver. Success of the attack would require bypassing the Windows memory protections such as Heap integrity and HSP. In addition, it requires a valid and running VPN IPSec connection.
- Source
- psirt@fortinet.com
- NVD status
- Modified
- Products
- forticlient
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 6
- Exploitability score
- 1.1
- Vector string
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- HIGH
- psirt@fortinet.com
- CWE-782
- Hype score
- Not currently trending
https://t.co/P9QiEvkceQ Highly dangerous vulnerabilities in FortiClient Windows The FortiGuard Labs security page warns of a highly dangerous vulnerability in FortiClient Windows. Fortinet lists the vulnerability under CVE-2025-47761, with a CVSS v3.1 score of 7.8. The update
@B2bCyber
30 Nov 2025
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Hochgefährliche Schwachstellen in FortiClient Windows https://t.co/tiTE6cPkl9 Die Security-Seite der FortiGuard Labs warnt vor einer hochgefährlichen Schwachstelle in FortiClient Windows. Fortinet führt unter der CVE-2025-47761 die Schwachstelle mit einem CVSS-v3.1-Wert von
@B2bCyber
29 Nov 2025
65 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️Vulnerabilidades en productos Fortinet ❗CVE-2025-58692 ❗CVE-2025-47761 ❗CVE-2025-46373 ➡️Más info: https://t.co/udVw71WvfO https://t.co/EwPgEvC4jz
@CERTpy
26 Nov 2025
110 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-47761 Local Privilege Escalation in Fortinet FortiClient Windows via Exposed IOCTL https://t.co/Sf8oTPwQRT
@VulmonFeeds
18 Nov 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*",
"matchCriteriaId": "F9DAAE56-ACF6-464C-AF20-68D9FE2C31B3",
"versionEndExcluding": "7.2.10",
"versionStartIncluding": "7.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*",
"matchCriteriaId": "51121FCA-2CA9-4B4B-A27C-C4729AB797BB",
"versionEndExcluding": "7.4.4",
"versionStartIncluding": "7.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]