Unrated severityNVD Advisory· Published Nov 18, 2025· Updated Jan 14, 2026
CVE-2025-46373
CVE-2025-46373
Description
A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via "fortips_74.sys". The attacker would need to bypass the Windows heap integrity protections
Affected products
2- Fortinet/FortiClientWindowsv5cpe:2.3:a:fortinet:forticlientwindows:7.4.3:*:*:*:*:*:*:*Range: 7.4.0
- Range: 7.2.0-7.2.8, 7.4.0-7.4.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.