CVE-2025-47761
published 2025-11-18CVE-2025-47761: An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows…
PriorityP343high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
EPSS
0.15%
5.1th percentile
An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips driver. Success of the attack would require bypassing the Windows memory protections such as Heap integrity and HSP. In addition, it requires a valid and running VPN IPSec connection.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | >= 7.2.0 < 7.2.10 | 7.2.10 |
| fortinet | forticlient | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | forticlientwindows | — | — |
| fortinet | forticlientwindows | 7.2.0 – 7.2.9 | — |
| fortinet | forticlientwindows | 7.4.0 – 7.4.3 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7...
vendor_fortinet·2025-11-18·CVSS 7.8
CVE-2025-47761 [HIGH] CWE-782 An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7...
FG-IR-25-112: An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7...
An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips driver. Success of the attack would require bypassing the Windows memory protections such as Heap integrity and HSP. In addition, it requires a valid and running VPN IPSec connection.
CVEs: CVE-2025-47761
CWEs: CWE-782
CVSS: 7.8 (high)
Affected products: FortiClient, FortiClientWindows, Fortinet
GHSA
GHSA-j48r-9cxh-ccpx: An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] in Fortinet FortiClientWindows 7
ghsa_unreviewed·2025-11-18
CVE-2025-47761 [HIGH] CWE-782 GHSA-j48r-9cxh-ccpx: An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] in Fortinet FortiClientWindows 7
An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips driver. Success of the attack would require bypassing the Windows memory protections such as Heap integrity and HSP. In addition, it requires a valid and running VPN IPSec connection.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24018 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-24018 [HIGH] CVE-2026-24018 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24018 :
FortiClient vulnerability analysis and mitigation
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
FortiClient
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:fortinet:forticlient
Sources
Linux Severity HIGH Has Fix Added at: Mar 14, 2026
Windows Severity HIGH Has Fix Added at: Mar 14, 2026
Linux Severity HIGH
Wiz
CVE-2025-62676 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-62676 [HIGH] CVE-2025-62676 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62676 :
FortiClient vulnerability analysis and mitigation
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.
Source : NVD
## 7.1
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
FortiClient
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:fortinet
2025-11-18
Published