ZeroHour
Fortinet PSIRTpublished ()ingested

Heap overflow in kernel driver due to missing size validation

highAdvisoryimportance 40
AI summary · glm-5.3-flash

Fortinet fixes a CVSS 7.3 heap overflow in the FortiClient Windows kernel driver enabling code execution via crafted DNS responses.

Fortinet PSIRT advisory FG-IR-26-156, revised 2026-08-12, describes a heap-based buffer overflow (CWE-120, buffer copy without checking input size) in the FortiClient Windows kernel driver, scored CVSSv3 7.3. An unauthenticated attacker positioned to alter or craft DNS responses for a targeted host could execute arbitrary code via malicious packets. No CVE identifier or exploitation status is provided in the advisory text, so administrators should check the full bulletin for affected versions and fixed releases.

  • CWE-120 buffer copy without input size validation in FortiClient Windows
  • Unauthenticated attacker able to alter DNS responses can execute arbitrary code
  • CVSSv3 score 7.3; advisory revised on 2026-08-12
VendorsFortinet
OrganizationsFortinet PSIRT
Full article

CVSSv3 Score: 7.3 A buffer copy without checking size of input vulnerability [CWE-120] in FortiClient Windows may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets. Revised on 2026-08-12 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.