CVE-2025-57716: High severity Fortinet FortiClient vulnerability
Published Oct 14, 2025
·Updated
An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer installation folder.
Affected Software
3 affected components
Fortinet FortiClient>=7.4.0<=7.4.3, >=7.2.0<=7.2.11, >=7.0
Fortinet FortiClient Windows>=7.0.0<7.2.12
Fortinet FortiClient Windows>=7.4.0<7.4.4
Remediation
Information
Upgrade to FortiClientWindows version 7.4.4 or above
Upgrade to FortiClientWindows version 7.2.12 or above
Event History
Oct 14, 2025
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-57716?
CVE-2025-57716 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-57716?
To fix CVE-2025-57716, upgrade FortiClient to version 7.4.4 or later.
3
Who is affected by CVE-2025-57716?
CVE-2025-57716 affects FortiClient versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, and all versions of 7.0.
4
What type of attack is associated with CVE-2025-57716?
CVE-2025-57716 is associated with a DLL hijacking attack due to an uncontrolled search path element.
5
Can CVE-2025-57716 be exploited by a remote attacker?
No, CVE-2025-57716 can only be exploited by a local low privileged user.