CVE-2025-54660
FortiClient vulnerability analysis and mitigation

Overview

CVE-2025-54660 is an active debug code vulnerability (CWE-489) in Fortinet FortiClientWindows that allows a local, low-privileged attacker to step through the application and retrieve saved VPN user passwords. It affects FortiClientWindows 7.4.0 through 7.4.3, 7.2.0 through 7.2.10, and all 7.0.x versions. The vulnerability was disclosed on November 18, 2025, and was reported by researchers from CrowdStrike under responsible disclosure. It carries a CVSS v3.1 base score of 4.9–5.5 (Medium), with a confidentiality-only impact (FortiGuard PSIRT, Feedly).

Technical details

The root cause is the presence of active debug code (CWE-489) left in production builds of FortiClientWindows, which exposes internal application state during step-by-step execution. A local attacker with low privileges can leverage debugging interfaces or tools to attach to the FortiClient process, step through its execution, and extract VPN credentials stored in memory or on disk. Exploitation requires local access to the system and at least a low-privileged user account; no network access or user interaction is needed. The attack vector is classified as local with low attack complexity (FortiGuard PSIRT).

Impact

Successful exploitation results in the disclosure of saved VPN user passwords, compromising the confidentiality of VPN credentials stored by FortiClientWindows. There is no integrity or availability impact. An attacker who retrieves these credentials could use them to authenticate to VPN services, potentially gaining unauthorized access to corporate networks and enabling lateral movement within the organization (FortiGuard PSIRT, Feedly).

Exploitation steps

  1. Local Access: Obtain a low-privileged local user account on a Windows system running a vulnerable version of FortiClientWindows (7.0.x, 7.2.0–7.2.10, or 7.4.0–7.4.3).
  2. Attach Debugger: Use a debugging tool (e.g., WinDbg, x64dbg, or OllyDbg) to attach to the FortiClientWindows process, leveraging the active debug code present in the production build.
  3. Step Through Execution: Use the debugger's step-through functionality to trace the application's execution flow, particularly around credential handling or VPN authentication routines.
  4. Extract VPN Credentials: Identify memory locations or variables where the saved VPN user password is stored in plaintext or a recoverable form during execution, and read the value directly from the debugger interface (FortiGuard PSIRT).

Indicators of compromise

  • Process: Unexpected debugger processes (e.g., windbg.exe, x64dbg.exe, ollydbg.exe) running concurrently with FortiClient.exe on endpoints.
  • Logs: Windows Security Event logs showing process injection or debug privilege (SeDebugPrivilege) usage by non-administrative accounts; Event ID 4688 showing unusual parent-child process relationships involving FortiClient.
  • File System: Presence of debugger tools or scripts in user-writable directories on systems running FortiClientWindows.
  • Network: Subsequent unauthorized VPN authentication attempts using credentials associated with accounts configured in FortiClientWindows, originating from unfamiliar IP addresses.

Mitigation and workarounds

Fortinet has released patched versions to address this vulnerability: upgrade FortiClientWindows 7.4.x to 7.4.4 or above, and FortiClientWindows 7.2.x to 7.2.11 or above. Users on FortiClientWindows 7.0.x (all versions) should migrate to a fixed release, as no patch is available for that branch. As interim mitigations, restrict local user access on systems running vulnerable versions, limit debug mode access, implement additional endpoint security controls, and consider rotating VPN credentials for potentially affected accounts (FortiGuard PSIRT).

Community reactions

The vulnerability was reported to Fortinet by Chris Elliott and Cameron Stokes from CrowdStrike under responsible disclosure, and Fortinet acknowledged their contribution in the official advisory (FortiGuard PSIRT). The CIS published an advisory noting multiple vulnerabilities in Fortinet products around the same disclosure period (CIS Advisory). Community reaction has been limited given the medium severity rating and absence of public exploits.

Additional resources


SourceThis report was generated using AI

Related FortiClient vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-24018HIGH7.8
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesMar 10, 2026
CVE-2025-47761HIGH7.8
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesNov 18, 2025
CVE-2025-62676HIGH7.1
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesFeb 10, 2026
CVE-2026-44278MEDIUM5.5
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesMay 12, 2026
CVE-2025-54660MEDIUM5.5
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesNov 18, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management