CVE-2025-62676 (ZDI-26-115 / ZDI-CAN-25710) is a local privilege escalation vulnerability in Fortinet FortiClientWindows (FortiClient VPN) affecting FortiClientWindows 7.4.0 through 7.4.4, 7.2.0 through 7.2.12, and 7.0 all versions. The flaw is in the FortiClient Configuration Daemon and is classified as improper link resolution before file access (CWE-59). A local low-privilege attacker can leverage crafted named pipe messages and filesystem link/junction manipulation to cause the service to follow a link and overwrite an attacker-chosen file, resulting in an arbitrary file write with elevated permissions and potential execution of attacker-controlled code as SYSTEM.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real Windows local privilege escalation PoC for CVE-2025-62676 against Fortinet FortiClient VPN. It is a Visual Studio solution with three main native C++ projects: FortiLPE (console launcher/orchestrator), NamedPipeDLL (injected helper DLL), and ExecDLL (proxy payload DLL). It also depends on the OffWinLib submodule plus Microsoft's WIL library. Exploit flow: FortiLPE locates FortiTray.exe, extracts two embedded DLLs to the temp directory, writes an XML application manifest that redirects oleaut32.dll loading to the dropped ExecDLL, creates a junction/object-manager symlink chain to that manifest, sets an oplock on the manifest, injects NamedPipeDLL into FortiTray.exe, waits for the privileged file access to occur, swaps the symlink target to C:\Windows\System32\CloudExperienceHostBroker.exe.manifest, then starts the scheduled task \Microsoft\Windows\CloudExperienceHost\CreateObjectTask. This causes CloudExperienceHostBroker.exe to run as SYSTEM and load the attacker-controlled proxy DLL via the external manifest. NamedPipeDLL is the primitive trigger. On load, it opens the FortiClient named pipe \\.\pipe\FC_{F18F86FD-7503-4564-80CF-B6B199519837}, derives a target XML path from its own DLL filename, builds a binary payload containing the arguments '-f <path> -o A', and writes that payload to the pipe. Per the README, this causes FortiClient to launch FCConfig.exe as SYSTEM and perform a read-then-write cycle on the attacker-chosen XML file, enabling the arbitrary file write when combined with oplock and symlink manipulation. ExecDLL is a proxy DLL for C:\Windows\System32\oleaut32.dll. It forwards many exports to the legitimate system DLL to preserve functionality, but in DllMain it executes a hardcoded command: 'cmd /c whoami > C:\whoami.txt'. This demonstrates code execution as SYSTEM. The payload is basic but functional, so the repository is best classified as OPERATIONAL rather than a mere POC without payload. Repository structure is consistent with a practical exploit implementation rather than a detector or documentation-only repo. The README clearly documents vulnerable versions, build/use steps, and the technical rationale for choosing CloudExperienceHostBroker.exe and the scheduled task trigger. No network C2 or remote exploitation behavior is present; the attack vector is local/file-based privilege escalation on Windows.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.