CVE-2025-46373: Buffer Overflow
A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via "fortips74.sys". The attacker would need to bypass the Windows heap integrity protections
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46373?
CVE-2025-46373 is considered a high-severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2025-46373?
To remediate CVE-2025-46373, update Fortinet FortiClient to the latest version beyond 7.4.3 or 7.2.8.
Who is affected by CVE-2025-46373?
Users of Fortinet FortiClient versions 7.4.0 through 7.4.3 and 7.2.0 through 7.2.8 are impacted by CVE-2025-46373.
What type of vulnerability is CVE-2025-46373?
CVE-2025-46373 is classified as a Heap-based Buffer Overflow vulnerability.
Can CVE-2025-46373 be exploited remotely?
No, CVE-2025-46373 requires an authenticated local IPSec user to exploit the vulnerability.