CVE-2025-47761: High severity Fortinet FortiClient vulnerability
An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips driver. Success of the attack would require bypassing the Windows memory protections such as Heap integrity and HSP. In addition, it requires a valid and running VPN IPSec connection.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47761?
CVE-2025-47761 is considered a high-severity vulnerability due to its potential for allowing unauthorized code execution.
How do I fix CVE-2025-47761?
To mitigate CVE-2025-47761, upgrade FortiClient to the latest version available, ensuring it is above 7.4.3 or 7.2.9.
Who is affected by CVE-2025-47761?
CVE-2025-47761 affects users of Fortinet FortiClient versions 7.4.0 to 7.4.3 and 7.2.0 to 7.2.9.
What type of vulnerability is CVE-2025-47761?
CVE-2025-47761 is categorized as an Exposed IOCTL with Insufficient Access Control vulnerability.
Can unauthorized users exploit CVE-2025-47761?
Yes, an authenticated local user can exploit CVE-2025-47761 to execute unauthorized code.