{"id":"CVE-2025-57716","title":"An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a maliciou…","summary":"An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a maliciou…","severity":"medium","cvss":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-427"],"vendor":"fortinet","product":"forticlient","affected":["forticlient >= 7.0.0, < 7.2.12","forticlient >= 7.4.0, < 7.4.4"],"patched":["forticlient 7.4.4"],"published":"2025-10-14","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-57716","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-25-685","label":"psirt@fortinet.com"}],"tags":["nvd"],"epss":0.00176,"epssPercentile":0.06603,"ingestedAt":"2026-10-08T11:31:27.390Z","slug":"CVE-2025-57716","body":"## Overview\n\nAn Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer installation folder.\n\n## Affected\n\n- `forticlient >= 7.0.0, < 7.2.12`\n- `forticlient >= 7.4.0, < 7.4.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `forticlient 7.4.4`","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":36.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}