Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ced_rtsystem
New Contributor

Question about FortiClient VPN SSL and CVE-2025-0167

Hello,

  our "Vulnerability Scanner" detected that libcurl.dll as vulnerable to CVE-2025-0167

Vulnerable files are:

  • C:\Program Files\Fortinet\FortiClient\libcurl.dll
  • C:\Program Files\Fortinet\FortiClient\x86\libcurl.dll

We use free FortiClient VPN SSL, so we can't confirm if full paid version is vulnerable too.

We've upgraded to FortiClient VPN SSL 7.4.3, but libcurl.dll version is still vulnerable

 

1 Solution
xshkurti
Staff
Staff

After going through the PSIRT website, there are no CVEs reported for this issue.

PSIRT Advisories | FortiGuard Labs

 

You can raise a request to Technical Support so we can track the issue with our FortiGuard Labs.

You can also check for libcurl.dll library to upgrade it separately:

Addressing CVE-2025-0167 vulnerability - How to upgrade curl and libcurl 8.12.0 - Microsoft Q&A

View solution in original post

2 REPLIES 2
xshkurti
Staff
Staff

After going through the PSIRT website, there are no CVEs reported for this issue.

PSIRT Advisories | FortiGuard Labs

 

You can raise a request to Technical Support so we can track the issue with our FortiGuard Labs.

You can also check for libcurl.dll library to upgrade it separately:

Addressing CVE-2025-0167 vulnerability - How to upgrade curl and libcurl 8.12.0 - Microsoft Q&A

ced_rtsystem

OK, Thanks!

 

We've sent a request to Fortinet PSIRT.

 

Manually changing libcurl.dll inside C:\Program Files\Fortinet, would require us to do it again the next time we update FortiClient.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors