CVE 7.1 HIGH

CVE-2025-47761_CVE-2025-47761

7.1 / 10
HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R

Description

An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips driver. Success of the attack would require bypassing the Windows memory protections such as Heap integrity and HSP. In addition, it requires a valid and running VPN IPSec connection.

Basic Information

ID CVE-2025-47761
Source fortinet
Published Nov 18, 2025 at 17:01
Modified Nov 18, 2025 at 21:11

Affected Product

Vendor Fortinet
Product FortiClientWindows
Version 7.4.0
Affected Versions Fortinet FortiClientWindows 7.4.0
Fortinet FortiClientWindows 7.2.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.