{"id":"CVE-2025-46373","details":"A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via \"fortips_74.sys\". The attacker would need to bypass the  Windows heap integrity protections","modified":"2026-03-13T03:19:13.938106Z","published":"2025-11-18T17:16:01.753Z","references":[{"type":"ADVISORY","url":"https://fortiguard.fortinet.com/psirt/FG-IR-25-125"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-46373.json","unresolved_ranges":[{"events":[{"introduced":"7.2.0"},{"fixed":"7.2.9"}]},{"events":[{"introduced":"7.4.0"},{"fixed":"7.4.4"}]}]}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}