Arbitrary XML file write in FCConfig

Summary

An Improper Link Resolution Before File Access vulnerability [CWE-59] in FortiClient Windows may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.

Version Affected Solution
FortiClientWindows 8.0 Not affected Not Applicable
FortiClientWindows 7.4 7.4.0 through 7.4.4 Upgrade to 7.4.5 or above
FortiClientWindows 7.2 7.2.0 through 7.2.12 Upgrade to 7.2.13 or above
FortiClientWindows 7.0 7.0 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Alexander Staalgaard working with TrendAI Zero Day Initiative for reporting this vulnerability under responsible disclosure.

Timeline

2026-02-10: Initial publication