CVE-2025-47761

An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips driver. Success of the attack would require bypassing the Windows memory protections such as Heap integrity and HSP. In addition, it requires a valid and running VPN IPSec connection.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*

History

No history.

Information

Published : 2025-11-18 17:16

Updated : 2025-12-16 11:15


NVD link : CVE-2025-47761

Mitre link : CVE-2025-47761

CVE.ORG link : CVE-2025-47761


JSON object : View

Products Affected

fortinet

  • forticlient
CWE
CWE-782

Exposed IOCTL with Insufficient Access Control