FortiClient and EMS
CVE-2025-62676: Link following in FortiClientWindows
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| FortiClientWindows 7.4.0 to 7.4.4 | 7.4.5 or later |
| FortiClientWindows 7.2.0 to 7.2.12 | 7.2.13 or later |
| FortiClientWindows 7.0.0 to 7.0.14 | Upgrade past 7.0.14; see the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.