CVE-2025-57716
An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hi
Severity
Medium 6
CVSS 3.1
Exploited
Not listed
EPSS
0.002
7.4th percentile
Discovered by
Third party
Vendor advisory field
Published
Oct 14, 2025
Assigned by fortinet
Description
An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer installation folder.
Weakness: CWE-427
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiClientWindows
Credit
Fortinet is pleased to thank Axel Flamcourt for reporting this vulnerability under responsible disclosure.
Vendor remediation
Upgrade to FortiClientWindows version 7.4.4 or above Upgrade to FortiClientWindows version 7.2.12 or above