A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3,… (CVE-2026-70465)
CVE-2026-70465 is a high-severity buffer overflow vulnerability in Fortinet FortiClient for Windows versions 7.4.0 through 7.4.3 and 7.2.0 through 7.2.11. It involves a buffer copy operation without verifying the size of the input, which may allow an unauthenticated attacker who can manipulate DNS responses to execute arbitrary code on the targeted host.
AI Analysis
Technical Summary
This vulnerability is a classic buffer overflow (CWE-120) in Fortinet FortiClient Windows versions 7.4.0 through 7.4.3 and 7.2.0 through 7.2.11. An attacker capable of altering or crafting DNS responses to the victim's machine can exploit this flaw by sending malicious packets that trigger a buffer copy without size checking, potentially leading to arbitrary code execution. The CVSS v3.1 base score is 8.1, indicating high severity with network attack vector, high attack complexity, no privileges or user interaction required, and impacts on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows remote unauthenticated attackers to execute arbitrary code on the affected system, potentially leading to full compromise of confidentiality, integrity, and availability of the host running FortiClient Windows in the specified versions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a patch is released, organizations should monitor vendor communications for updates and consider network-level protections to detect or block malicious DNS responses.
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3,… (CVE-2026-70465)
Description
CVE-2026-70465 is a high-severity buffer overflow vulnerability in Fortinet FortiClient for Windows versions 7.4.0 through 7.4.3 and 7.2.0 through 7.2.11. It involves a buffer copy operation without verifying the size of the input, which may allow an unauthenticated attacker who can manipulate DNS responses to execute arbitrary code on the targeted host.
CVSS v3.1
Score 8.1high
Affected software
pkg:github/fortinet/forticlient-windowsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability is a classic buffer overflow (CWE-120) in Fortinet FortiClient Windows versions 7.4.0 through 7.4.3 and 7.2.0 through 7.2.11. An attacker capable of altering or crafting DNS responses to the victim's machine can exploit this flaw by sending malicious packets that trigger a buffer copy without size checking, potentially leading to arbitrary code execution. The CVSS v3.1 base score is 8.1, indicating high severity with network attack vector, high attack complexity, no privileges or user interaction required, and impacts on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows remote unauthenticated attackers to execute arbitrary code on the affected system, potentially leading to full compromise of confidentiality, integrity, and availability of the host running FortiClient Windows in the specified versions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a patch is released, organizations should monitor vendor communications for updates and consider network-level protections to detect or block malicious DNS responses.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-95wv-6wmf-f8vm
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-70465"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a7c9b4abf8831d539cdd5e9
Added to database: 08/12/2026, 16:11:54 UTC
Last enriched: 08/12/2026, 16:57:44 UTC
Last updated: 08/13/2026, 02:41:00 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.