DLL Hijacking Vulnerability in FortiClient by Fortinet
CVE-2025-57716

6MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
14 October 2025

What is CVE-2025-57716?

A vulnerability exists in FortiClient that allows a local low-privileged user to exploit an uncontrolled search path element. By placing a malicious DLL in the FortiClient Online Installer installation folder, an attacker may execute unauthorized code. This can lead to significant security breaches, making systems vulnerable to various forms of exploitation if not properly mitigated.

Affected Version(s)

FortiClientWindows 7.4.0 <= 7.4.3

FortiClientWindows 7.2.0 <= 7.2.11

FortiClientWindows 7.0.0 <= 7.0.14

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-57716 : DLL Hijacking Vulnerability in FortiClient by Fortinet