
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-47761 is an Exposed IOCTL with Insufficient Access Control vulnerability (CWE-782) in Fortinet FortiClient Windows that may allow an authenticated local user to execute unauthorized code via the fortips driver. It affects FortiClientWindows versions 7.4.0 through 7.4.3 and 7.2.0 through 7.2.9. The vulnerability was disclosed on November 18, 2025, and was reported by Alex of HackerHood Research Group under responsible disclosure. It carries a CVSS v3.1 base score of 7.8 (High) per NVD, and 7.1 (High) per Fortinet's own advisory (FortiGuard PSIRT, Red Hat CVE).
The vulnerability is classified as CWE-782 (Exposed IOCTL with Insufficient Access Control) and resides in the fortips kernel driver component of FortiClient Windows. The driver exposes an IOCTL interface without adequate access restrictions, enabling an authenticated local user to trigger an arbitrary memory write operation. Exploitation requires two significant preconditions: a valid and running VPN IPSec connection must be active, and the attacker must successfully bypass Windows memory protections including Heap Integrity and Hardware Stack Protection (HSP). The attack vector is local, requires low privileges, and no user interaction, but the high attack complexity reflects the memory protection bypass requirement (FortiGuard PSIRT, Red Hat CVE).
Successful exploitation could allow an authenticated local attacker to execute unauthorized code in the context of the kernel driver, resulting in high confidentiality, integrity, and availability impact with a changed scope — meaning the compromise can extend beyond the FortiClient process itself to the underlying Windows system. This could lead to privilege escalation, unauthorized access to sensitive data, and potential disruption of system availability. The requirement for an active IPSec VPN connection limits the attack surface to systems actively using FortiClient's VPN functionality (FortiGuard PSIRT).
fortips kernel driver, which lacks sufficient access control validation.fortips driver; Security event log entries for privilege escalation attempts.System32) by non-administrative processes; new scheduled tasks or services created post-exploitation.fortips driver observable via kernel debugging or EDR telemetry; unexpected memory modifications in kernel space.Fortinet has released patched versions to address this vulnerability. Users should upgrade FortiClient Windows to version 7.4.4 or later (for the 7.4.x branch) or 7.2.10 or later (for the 7.2.x branch). The FortiClient Windows free VPN-Only version 7.4.3.1761.1.8758 also contains the patch. As interim mitigations, organizations should restrict local user privileges, monitor and limit VPN IPSec connections to only authorized users, and implement robust endpoint detection solutions to identify anomalous driver interactions (FortiGuard PSIRT).
The CIS published an advisory noting that multiple vulnerabilities in Fortinet products, including CVE-2025-47761, could allow for arbitrary code execution (CIS Advisory). Red Hot Cyber covered the vulnerability with framing around privilege escalation risk in FortiClient VPN (Red Hot Cyber). A technical blog post on building a Windows driver vulnerability analyzer referenced this CVE as a case study, indicating some researcher interest in the driver-level attack surface (Threat Unpacked). Overall community reaction has been measured, reflecting the high exploitation complexity and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."