CVE-2025-24473

A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an una

Severity
Medium 4.8
CVSS 3.1
Exploited
Not listed
EPSS
0.005
44.8th percentile
Discovered by
Third party
Vendor advisory field
Published
May 28, 2025
Assigned by fortinet

Description

A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured to accept incoming connections to port 8053 (non-default setup)

Weakness: CWE-497

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiClientWindows

Credit

Fortinet is pleased to thank Víctor A. Morales from GM Sectec, Inc. for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiClientWindows version 7.2.2 or above

Something wrong here?