ZeroHour
Fortinet PSIRTpublished ()ingested

Arbitrary process termination from exposed minifilter communication port

lowAdvisoryimportance 15
AI summary · glm-5.3

Fortinet FortiClient Windows fortimon3 driver flaw (CVSS 4.7) lets authenticated attackers terminate arbitrary processes via exposed minifilter communication port.

Fortinet advisory FG-IR-26-165 discloses an unverified ownership vulnerability (CWE-283, CVSSv3 4.7) in the FortiClient Windows fortimon3 minifilter driver. An authenticated attacker can terminate arbitrary processes through an exposed minifilter communication port. The advisory was revised on 2026-09-08.

  • Unverified ownership (CWE-283) in FortiClient fortimon3 driver, CVSSv3 4.7
  • Exposed minifilter communication port allows arbitrary process termination
  • Requires an authenticated attacker, impact limited to denial of service
Full article

CVSSv3 Score: 4.7 An Unverified Ownership Vulnerability [CWE-283] in FortiClient Windows fortimon3 driver may allow an authenticated attacker to terminate arbitrary processes via an exposed minifilter communication port. Revised on 2026-09-08 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.