CVE-2025-47761
FortiClient vulnerability analysis and mitigation

Overview

CVE-2025-47761 is an Exposed IOCTL with Insufficient Access Control vulnerability (CWE-782) in Fortinet FortiClient Windows that may allow an authenticated local user to execute unauthorized code via the fortips driver. It affects FortiClientWindows versions 7.4.0 through 7.4.3 and 7.2.0 through 7.2.9. The vulnerability was disclosed on November 18, 2025, and was reported by Alex of HackerHood Research Group under responsible disclosure. It carries a CVSS v3.1 base score of 7.8 (High) per NVD, and 7.1 (High) per Fortinet's own advisory (FortiGuard PSIRT, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-782 (Exposed IOCTL with Insufficient Access Control) and resides in the fortips kernel driver component of FortiClient Windows. The driver exposes an IOCTL interface without adequate access restrictions, enabling an authenticated local user to trigger an arbitrary memory write operation. Exploitation requires two significant preconditions: a valid and running VPN IPSec connection must be active, and the attacker must successfully bypass Windows memory protections including Heap Integrity and Hardware Stack Protection (HSP). The attack vector is local, requires low privileges, and no user interaction, but the high attack complexity reflects the memory protection bypass requirement (FortiGuard PSIRT, Red Hat CVE).

Impact

Successful exploitation could allow an authenticated local attacker to execute unauthorized code in the context of the kernel driver, resulting in high confidentiality, integrity, and availability impact with a changed scope — meaning the compromise can extend beyond the FortiClient process itself to the underlying Windows system. This could lead to privilege escalation, unauthorized access to sensitive data, and potential disruption of system availability. The requirement for an active IPSec VPN connection limits the attack surface to systems actively using FortiClient's VPN functionality (FortiGuard PSIRT).

Exploitation steps

  1. Precondition – Local Access: Obtain authenticated local access to a Windows system running a vulnerable version of FortiClient Windows (7.2.0–7.2.9 or 7.4.0–7.4.3) with low-privilege credentials.
  2. Precondition – Active VPN: Ensure a valid and running VPN IPSec connection is established through FortiClient, as this is a hard requirement for the vulnerability to be reachable.
  3. Memory Protection Bypass: Develop or obtain a technique to bypass Windows memory protections, specifically Heap Integrity checking and Hardware Stack Protection (HSP), which guard against kernel-level memory corruption.
  4. IOCTL Interaction: Craft a malicious IOCTL request targeting the exposed interface in the fortips kernel driver, which lacks sufficient access control validation.
  5. Arbitrary Memory Write: Send the crafted IOCTL to trigger an arbitrary memory write primitive within the driver, enabling kernel-level code execution.
  6. Privilege Escalation / Code Execution: Leverage the kernel code execution to escalate privileges or execute arbitrary payloads on the compromised system (FortiGuard PSIRT).

Indicators of compromise

  • Process: Unexpected processes spawned with elevated (SYSTEM) privileges from a low-privilege user session on systems running FortiClient Windows.
  • Logs: Windows Event Logs showing unusual kernel driver interactions or access control failures related to the fortips driver; Security event log entries for privilege escalation attempts.
  • Network: Active IPSec VPN sessions on endpoints where no legitimate VPN usage is expected; unusual outbound connections from systems running FortiClient.
  • File System: Unexpected files or executables written to privileged directories (e.g., System32) by non-administrative processes; new scheduled tasks or services created post-exploitation.
  • Driver/Kernel: Anomalous IOCTL calls to the fortips driver observable via kernel debugging or EDR telemetry; unexpected memory modifications in kernel space.

Mitigation and workarounds

Fortinet has released patched versions to address this vulnerability. Users should upgrade FortiClient Windows to version 7.4.4 or later (for the 7.4.x branch) or 7.2.10 or later (for the 7.2.x branch). The FortiClient Windows free VPN-Only version 7.4.3.1761.1.8758 also contains the patch. As interim mitigations, organizations should restrict local user privileges, monitor and limit VPN IPSec connections to only authorized users, and implement robust endpoint detection solutions to identify anomalous driver interactions (FortiGuard PSIRT).

Community reactions

The CIS published an advisory noting that multiple vulnerabilities in Fortinet products, including CVE-2025-47761, could allow for arbitrary code execution (CIS Advisory). Red Hot Cyber covered the vulnerability with framing around privilege escalation risk in FortiClient VPN (Red Hot Cyber). A technical blog post on building a Windows driver vulnerability analyzer referenced this CVE as a case study, indicating some researcher interest in the driver-level attack surface (Threat Unpacked). Overall community reaction has been measured, reflecting the high exploitation complexity and absence of active exploitation.

Additional resources


SourceThis report was generated using AI

Related FortiClient vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-24018HIGH7.8
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesMar 10, 2026
CVE-2025-47761HIGH7.8
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesNov 18, 2025
CVE-2025-62676HIGH7.1
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesFeb 10, 2026
CVE-2026-44278MEDIUM5.5
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesMay 12, 2026
CVE-2025-54660MEDIUM5.5
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesNov 18, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management