CVE-2025-62676
FortiClient vulnerability analysis and mitigation

Overview

CVE-2025-62676 is an Improper Link Resolution Before File Access ('Link Following') vulnerability (CWE-59) in Fortinet FortiClientWindows that allows a local low-privilege attacker to perform arbitrary file writes with elevated permissions via crafted named pipe messages. Affected versions include FortiClientWindows 7.4.0 through 7.4.4, 7.2.0 through 7.2.12, and all 7.0.x versions; FortiClientWindows 8.0 is not affected. The vulnerability was publicly disclosed on February 10, 2026, with a ZDI advisory published February 19, 2026. It carries a CVSS v3.1 base score of 7.1 (High) per Feedly/NVD data, while Fortinet's own advisory rates it 6.4 (Medium) (Fortinet PSIRT, Red Hat CVE).

Technical details

The root cause is CWE-59 (Improper Link Resolution Before File Access / 'Link Following'), where the FortiClientWindows FCConfig component fails to properly validate symbolic or junction link targets before performing file operations. A local attacker with low privileges can send crafted named pipe messages to a privileged FortiClient service, causing it to follow a malicious link and write attacker-controlled content to an arbitrary file location with elevated (SYSTEM-level) permissions. Exploitation requires local access and low-privilege credentials but no user interaction. The vulnerability was discovered externally by Alexander Staalgaard working with Trend Micro's Zero Day Initiative and reported under responsible disclosure (Fortinet PSIRT, ZDI Advisory).

Impact

Successful exploitation allows a local low-privilege attacker to write arbitrary files with elevated (SYSTEM-level) permissions, resulting in high integrity and high availability impact with no confidentiality impact. An attacker could overwrite critical system or application files, install malware, create backdoors, or cause denial of service by corrupting essential files. This constitutes a local privilege escalation that could serve as a stepping stone for broader system compromise on affected Windows endpoints (Fortinet PSIRT, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify target Windows systems running vulnerable FortiClientWindows versions (7.0.x, 7.2.0–7.2.12, or 7.4.0–7.4.4) with local access as a low-privilege user.
  2. Identify named pipe: Locate the named pipe exposed by the privileged FortiClient FCConfig service (e.g., using tools like PipeList or Process Hacker) that accepts configuration messages.
  3. Create malicious symlink/junction: As a low-privilege user, create a symbolic link or directory junction pointing from a path the FortiClient service will write to, redirecting it to a sensitive target file (e.g., a system binary or startup script).
  4. Craft and send named pipe message: Send a specially crafted named pipe message to the FortiClient service that triggers a file write operation, causing the service to follow the malicious link and write attacker-controlled content to the redirected target path with SYSTEM privileges.
  5. Achieve privilege escalation: The arbitrary file write at a privileged location (e.g., overwriting a service executable or adding a malicious DLL) is then leveraged to execute code as SYSTEM, completing local privilege escalation (Fortinet PSIRT, ZDI Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by FortiClient services (e.g., cmd.exe, powershell.exe) running under SYSTEM context.
  • File System: Unexpected modifications to system files or directories (e.g., C:\Windows\System32\, service executables) with timestamps correlating to FortiClient service activity; newly created symbolic links or junction points in FortiClient-related directories.
  • Logs: Windows Security Event Log entries showing file write operations by FortiClient service accounts (NT AUTHORITY\SYSTEM) to unusual paths; Event ID 4663 (file object access) targeting sensitive system files.
  • Network: Named pipe activity to FortiClient-related pipes from unexpected low-privilege user processes (observable via Sysmon Event ID 17/18 for pipe creation/connection).
  • Registry: Unexpected changes to service configurations or autorun keys that could indicate persistence established via the arbitrary file write (Fortinet PSIRT).

Mitigation and workarounds

Fortinet has released patched versions addressing this vulnerability: upgrade FortiClientWindows 7.4.x to 7.4.5 or later, and FortiClientWindows 7.2.x to 7.2.13 or later. All FortiClientWindows 7.0.x users must migrate to a fixed release, as no patch will be issued for that branch. As interim mitigations, restrict local user access to affected systems where feasible and monitor for suspicious named pipe activity and unauthorized file modifications. FortiClientWindows 8.0 is not affected and requires no action (Fortinet PSIRT).

Community reactions

The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Fortinet products that could allow for arbitrary code execution, grouping CVE-2025-62676 among them (CIS Advisory). Belgium's Centre for Cybersecurity (CCB) also issued a warning advising immediate patching of affected Fortinet products. The vulnerability was responsibly disclosed by Alexander Staalgaard through Trend Micro's Zero Day Initiative, which published advisory ZDI-26-115 on February 19, 2026 (ZDI Advisory). Community reaction has been measured given the local-only attack vector and absence of public exploit code.

Additional resources


SourceThis report was generated using AI

Related FortiClient vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-24018HIGH7.8
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesMar 10, 2026
CVE-2025-47761HIGH7.8
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesNov 18, 2025
CVE-2025-62676HIGH7.1
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesFeb 10, 2026
CVE-2026-44278MEDIUM5.5
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesMay 12, 2026
CVE-2025-54660MEDIUM5.5
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesNov 18, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management