CVE-2026-70465

Summary

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.

Affected Software

VendorProductVersion RangeStatus
FortinetFortiClientWindows7.4.0 <= 7.4.3affected
FortinetFortiClientWindows7.2.0 <= 7.2.11affected

Weaknesses

  • CWE-120: Escalation of privilege

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References