CVE-2025-46373
published 2025-11-18CVE-2025-46373: A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8…
PriorityP344high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
EPSS
0.15%
4.6th percentile
A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via "fortips_74.sys". The attacker would need to bypass the Windows heap integrity protections
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | >= 7.2.0 < 7.2.9 | 7.2.9 |
| fortinet | forticlient | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | forticlientwindows | — | — |
| fortinet | forticlientwindows | 7.2.0 – 7.2.8 | — |
| fortinet | forticlientwindows | 7.4.0 – 7.4.3 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, F...
vendor_fortinet·2025-11-18·CVSS 7.8
CVE-2025-46373 [HIGH] CWE-122 A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, F...
FG-IR-25-125: A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, F...
A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via "fortips_74.sys". The attacker would need to bypass the Windows heap integrity protections
CVEs: CVE-2025-46373
CWEs: CWE-122
CVSS: 7.8 (high)
Affected products: FortiClient, FortiClientWindows, Fortinet
GHSA
GHSA-mjrx-5jw9-2x26: A Heap-based Buffer Overflow vulnerability [CWE-122] in Fortinet FortiClientWindows 7
ghsa_unreviewed·2025-11-18
CVE-2025-46373 [HIGH] CWE-122 GHSA-mjrx-5jw9-2x26: A Heap-based Buffer Overflow vulnerability [CWE-122] in Fortinet FortiClientWindows 7
A Heap-based Buffer Overflow vulnerability [CWE-122] in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via "fortips_74.sys". The attacker would need to bypass the Windows heap integrity protections
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24018 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-24018 [HIGH] CVE-2026-24018 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24018 :
FortiClient vulnerability analysis and mitigation
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
FortiClient
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:fortinet:forticlient
Sources
Linux Severity HIGH Has Fix Added at: Mar 14, 2026
Windows Severity HIGH Has Fix Added at: Mar 14, 2026
Linux Severity HIGH
Wiz
CVE-2025-62676 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-62676 [HIGH] CVE-2025-62676 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62676 :
FortiClient vulnerability analysis and mitigation
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.
Source : NVD
## 7.1
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
FortiClient
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:fortinet
2025-11-18
Published