Junglewise Threat Intelligence

CVE-2026-84386: Fortinet FortiClient Windows arbitrary process termination in minifilter driver

CVE-2026-84386 · Severity: medium · CVSS 5.1 · Published 2026-09-08

Vendors: Fortinet.

Executive brief

Fortinet FortiClient Windows is an endpoint security client deployed on employee workstations. An authenticated attacker can terminate arbitrary processes on an affected system by exploiting an unverified ownership vulnerability in the minifilter communication driver, potentially disrupting business operations or disabling security controls.

Technical details

The vulnerability is an unverified ownership issue (CWE-283) in the fortimon3 minifilter driver that allows an authenticated attacker to terminate arbitrary processes via an exposed minifilter communication port. The attack requires local system access and authentication but no elevated privileges. An attacker with valid credentials or local access can use this exposed communication channel to send termination commands to the kernel driver, affecting any running process. The vulnerability affects FortiClient Windows versions 7.2 (all versions) and 7.4.0 through 7.4.7; users are advised to upgrade to version 7.4.8 or migrate to version 8.0.

Affected products

  • Fortinet FortiClient Windows 7.2 all versions, 7.4.0 through 7.4.7

Timeline

  • 2026-09-08: disclosed

References

Related threats