CVE-2025-57716
An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hi
Severity
Medium 6
CVSS 3.1
Exploited
Not listed
EPSS
0.002
6.1th percentile
Discovered by
Not disclosed
Published
Oct 14, 2025
Assigned by fortinet
Description
An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer installation folder.
Weakness: CWE-427
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiClientWindows
Vendor remediation
Upgrade to FortiClientWindows version 7.4.4 or above Upgrade to FortiClientWindows version 7.2.12 or above