{"id":"CVE-2026-70465","title":"A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alt…","summary":"A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alt…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-120"],"vendor":"fortinet","product":"forticlient","affected":["forticlient >= 7.2.0, < 7.2.12","forticlient >= 7.4.0, < 7.4.4"],"patched":["forticlient 7.4.4"],"published":"2026-08-12","updated":"2026-09-08","sourceUpdated":"2026-09-08T21:03:37.110","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-70465","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-156","label":"psirt@fortinet.com"}],"tags":["nvd"],"epss":0.00667,"epssPercentile":0.50054,"ingestedAt":"2026-09-08T21:11:12.275Z","slug":"CVE-2026-70465","body":"## Overview\n\nA buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.\n\n## Affected\n\n- `forticlient >= 7.2.0, < 7.2.12`\n- `forticlient >= 7.4.0, < 7.4.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `forticlient 7.4.4`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}