VYPR
Unrated severityNVD Advisory· Published Nov 18, 2025· Updated Jan 14, 2026

CVE-2025-46373

CVE-2025-46373

Description

A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via "fortips_74.sys". The attacker would need to bypass the Windows heap integrity protections

Affected products

2
  • Fortinet/FortiClientWindowsv5
    cpe:2.3:a:fortinet:forticlientwindows:7.4.3:*:*:*:*:*:*:*
    Range: 7.4.0
  • Range: 7.2.0-7.2.8, 7.4.0-7.4.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.