CVE-2026-70465 PUBLISHED

Assigner: fortinet
Reserved: 04.08.2026 Published: 12.08.2026 Updated: 12.08.2026

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CVSS Score: 7.3

Product Status

Vendor Fortinet
Product FortiClientWindows
Versions Default: unaffected
  • affected from 7.4.0 to 7.4.3 (incl.)
  • affected from 7.2.0 to 7.2.11 (incl.)

Solutions

Upgrade to FortiClientWindows version 7.4.4 or above Upgrade to FortiClientWindows version 7.2.12 or above

References

Problem Types

  • Escalation of privilege CWE