Description
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.
Published: 2026-08-12
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FortiClientWindows contains a classic buffer overflow flaw caused by an unchecked memory copy operation. This vulnerability allows an attacker to embed oversized data into a buffer during DNS response processing, which can lead to arbitrary code execution in the context of the FortiClient service. Because the flaw is triggered by malformed DNS packets, an unauthenticated attacker can potentially exploit the host simply by sending crafted DNS replies, enabling the attacker to run malicious code, exfiltrate data, or disrupt network operations.

Affected Systems

Fortinet FortiClientWindows versions 7.2.0 through 7.2.11 and 7.4.0 through 7.4.3 are impacted. The weakness resides in the core network component that parses DNS responses. All installations of these releases running on Windows machines in corporate environments are potentially susceptible unless patched.

Risk and Exploitability

The CVSS score of 7.3 classifies this flaw as High severity. The lack of authentication requirement and network‑based attack vector mean that any external host capable of reaching the affected client can issue the malicious DNS requests needed to trigger the overflow. EPSS data are unavailable, so exact exploitation probability is unknown; however, the high score and potential for bypassing normal firewall rules underline the need for prompt remediation. The vulnerability is not yet listed in CISA’s KEV catalog, suggesting no publicly confirmed exploits at this time, but the risk remains significant.

Generated by OpenCVE AI on August 13, 2026 at 01:06 UTC.

Remediation

Vendor Solution

Upgrade to FortiClientWindows version 7.4.4 or above Upgrade to FortiClientWindows version 7.2.12 or above


OpenCVE Recommended Actions

  • Apply the FortiClientWindows upgrade to version 7.4.4 or later, or to 7.2.12 or later if using the 7.2 series.
  • Limit DNS traffic to the FortiClient service by configuring firewall rules to allow DNS responses only from trusted sources.
  • Run the FortiClient service under a non‑administrative user account to reduce the impact scope if the vulnerability is exploited.

Generated by OpenCVE AI on August 13, 2026 at 01:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated DNS Buffer Overflow Enables Arbitrary Code Execution in FortiClientWindows

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.
First Time appeared Fortinet
Fortinet forticlientwindows
Weaknesses CWE-120
CPEs cpe:2.3:a:fortinet:forticlientwindows:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.4.3:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet forticlientwindows
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}


Subscriptions

Fortinet Forticlientwindows
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-08-13T03:55:27.282Z

Reserved: 2026-08-04T15:01:40.657Z

Link: CVE-2026-70465

cve-icon Vulnrichment

Updated: 2026-08-12T12:26:24.711Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T12:19:47.017

Modified: 2026-08-26T16:54:50.030

Link: CVE-2026-70465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:15:12Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')