{
 "description": "Evidence-bound MITRE ATT&CK techniques observed in ctipilot.ch entries referencing Fortinet FortiClient for Windows \u2014 buffer copy without size check lets an unauthenticated attacker able to alter or craft DNS responses execute arbitrary code (CVSS 8.1); fixed in 7.4.4 / 7.2.12. Score = number of published entries mapping the technique. Pinned dataset: ATT&CK v19.2.",
 "domain": "enterprise-attack",
 "gradient": {
  "colors": [
   "#ffe766",
   "#ff6666"
  ],
  "maxValue": 1,
  "minValue": 0
 },
 "hideDisabled": false,
 "layout": {
  "layout": "side",
  "showID": true,
  "showName": true
 },
 "legendItems": [],
 "metadata": [
  {
   "name": "source",
   "value": "ctipilot.ch"
  },
  {
   "name": "entity",
   "value": "CVE-2026-70465"
  },
  {
   "name": "attack_version",
   "value": "19.2"
  }
 ],
 "name": "Fortinet FortiClient for Windows \u2014 buffer copy without size check lets an unauthenticated attacker able to alter or craft DNS responses execute arbitrary code (CVSS 8.1); fixed in 7.4.4 / 7.2.12 \u2014 ctipilot.ch coverage",
 "sorting": 3,
 "techniques": [
  {
   "comment": "entries: 2026-08-15/fortiweb-radius-wildcard-bypass-fortimanager-fgfm",
   "score": 1,
   "techniqueID": "T1078"
  },
  {
   "comment": "entries: 2026-08-15/fortiweb-radius-wildcard-bypass-fortimanager-fgfm",
   "score": 1,
   "techniqueID": "T1190"
  },
  {
   "comment": "entries: 2026-08-15/fortiweb-radius-wildcard-bypass-fortimanager-fgfm",
   "score": 1,
   "techniqueID": "T1557"
  }
 ],
 "versions": {
  "attack": "19",
  "layer": "4.5",
  "navigator": "5.1.0"
 }
}