DLL Hijacking Vulnerability in FortiClient by Fortinet
CVE-2025-57716
6MEDIUM
What is CVE-2025-57716?
A vulnerability exists in FortiClient that allows a local low-privileged user to exploit an uncontrolled search path element. By placing a malicious DLL in the FortiClient Online Installer installation folder, an attacker may execute unauthorized code. This can lead to significant security breaches, making systems vulnerable to various forms of exploitation if not properly mitigated.
Affected Version(s)
FortiClientWindows 7.4.0 <= 7.4.3
FortiClientWindows 7.2.0 <= 7.2.11
FortiClientWindows 7.0.0 <= 7.0.14