High SEVERITY — Vulnerability

Heap overflow in kernel driver due to missing size validation

CVSSv3 Score: 7.3 A buffer copy without checking size of input vulnerability in FortiClient Windows may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets. Revised on 2026-08-12 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
7.3/10
Advisory
FG-IR-26-156
Published
12 August 2026
Views
47
Primary source: Review the official advisory at fortiguard.fortinet.com Go to Source

Summary

CVSSv3 Score: 7.3 A buffer copy without checking size of input vulnerability in FortiClient Windows may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets. Revised on 2026-08-12 00:00:00

Source

FortiGate / FortiOS — Related Advisories

VIEW ALL →