
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62676 is an Improper Link Resolution Before File Access ('Link Following') vulnerability (CWE-59) in Fortinet FortiClientWindows that allows a local low-privilege attacker to perform arbitrary file writes with elevated permissions via crafted named pipe messages. Affected versions include FortiClientWindows 7.4.0 through 7.4.4, 7.2.0 through 7.2.12, and all 7.0.x versions; FortiClientWindows 8.0 is not affected. The vulnerability was publicly disclosed on February 10, 2026, with a ZDI advisory published February 19, 2026. It carries a CVSS v3.1 base score of 7.1 (High) per Feedly/NVD data, while Fortinet's own advisory rates it 6.4 (Medium) (Fortinet PSIRT, Red Hat CVE).
The root cause is CWE-59 (Improper Link Resolution Before File Access / 'Link Following'), where the FortiClientWindows FCConfig component fails to properly validate symbolic or junction link targets before performing file operations. A local attacker with low privileges can send crafted named pipe messages to a privileged FortiClient service, causing it to follow a malicious link and write attacker-controlled content to an arbitrary file location with elevated (SYSTEM-level) permissions. Exploitation requires local access and low-privilege credentials but no user interaction. The vulnerability was discovered externally by Alexander Staalgaard working with Trend Micro's Zero Day Initiative and reported under responsible disclosure (Fortinet PSIRT, ZDI Advisory).
Successful exploitation allows a local low-privilege attacker to write arbitrary files with elevated (SYSTEM-level) permissions, resulting in high integrity and high availability impact with no confidentiality impact. An attacker could overwrite critical system or application files, install malware, create backdoors, or cause denial of service by corrupting essential files. This constitutes a local privilege escalation that could serve as a stepping stone for broader system compromise on affected Windows endpoints (Fortinet PSIRT, Red Hat CVE).
cmd.exe, powershell.exe) running under SYSTEM context.C:\Windows\System32\, service executables) with timestamps correlating to FortiClient service activity; newly created symbolic links or junction points in FortiClient-related directories.NT AUTHORITY\SYSTEM) to unusual paths; Event ID 4663 (file object access) targeting sensitive system files.Fortinet has released patched versions addressing this vulnerability: upgrade FortiClientWindows 7.4.x to 7.4.5 or later, and FortiClientWindows 7.2.x to 7.2.13 or later. All FortiClientWindows 7.0.x users must migrate to a fixed release, as no patch will be issued for that branch. As interim mitigations, restrict local user access to affected systems where feasible and monitor for suspicious named pipe activity and unauthorized file modifications. FortiClientWindows 8.0 is not affected and requires no action (Fortinet PSIRT).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Fortinet products that could allow for arbitrary code execution, grouping CVE-2025-62676 among them (CIS Advisory). Belgium's Centre for Cybersecurity (CCB) also issued a warning advising immediate patching of affected Fortinet products. The vulnerability was responsibly disclosed by Alexander Staalgaard through Trend Micro's Zero Day Initiative, which published advisory ZDI-26-115 on February 19, 2026 (ZDI Advisory). Community reaction has been measured given the local-only attack vector and absence of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."