
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-54660 is an active debug code vulnerability (CWE-489) in Fortinet FortiClientWindows that allows a local, low-privileged attacker to step through the application and retrieve saved VPN user passwords. It affects FortiClientWindows 7.4.0 through 7.4.3, 7.2.0 through 7.2.10, and all 7.0.x versions. The vulnerability was disclosed on November 18, 2025, and was reported by researchers from CrowdStrike under responsible disclosure. It carries a CVSS v3.1 base score of 4.9–5.5 (Medium), with a confidentiality-only impact (FortiGuard PSIRT, Feedly).
The root cause is the presence of active debug code (CWE-489) left in production builds of FortiClientWindows, which exposes internal application state during step-by-step execution. A local attacker with low privileges can leverage debugging interfaces or tools to attach to the FortiClient process, step through its execution, and extract VPN credentials stored in memory or on disk. Exploitation requires local access to the system and at least a low-privileged user account; no network access or user interaction is needed. The attack vector is classified as local with low attack complexity (FortiGuard PSIRT).
Successful exploitation results in the disclosure of saved VPN user passwords, compromising the confidentiality of VPN credentials stored by FortiClientWindows. There is no integrity or availability impact. An attacker who retrieves these credentials could use them to authenticate to VPN services, potentially gaining unauthorized access to corporate networks and enabling lateral movement within the organization (FortiGuard PSIRT, Feedly).
windbg.exe, x64dbg.exe, ollydbg.exe) running concurrently with FortiClient.exe on endpoints.SeDebugPrivilege) usage by non-administrative accounts; Event ID 4688 showing unusual parent-child process relationships involving FortiClient.Fortinet has released patched versions to address this vulnerability: upgrade FortiClientWindows 7.4.x to 7.4.4 or above, and FortiClientWindows 7.2.x to 7.2.11 or above. Users on FortiClientWindows 7.0.x (all versions) should migrate to a fixed release, as no patch is available for that branch. As interim mitigations, restrict local user access on systems running vulnerable versions, limit debug mode access, implement additional endpoint security controls, and consider rotating VPN credentials for potentially affected accounts (FortiGuard PSIRT).
The vulnerability was reported to Fortinet by Chris Elliott and Cameron Stokes from CrowdStrike under responsible disclosure, and Fortinet acknowledged their contribution in the official advisory (FortiGuard PSIRT). The CIS published an advisory noting multiple vulnerabilities in Fortinet products around the same disclosure period (CIS Advisory). Community reaction has been limited given the medium severity rating and absence of public exploits.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."