← Back to driver explorer
Driver intelligenceVulnerableVerified

fortimon3.sys

Fortinet FortiClient's fortimon3.sys minifilter exposes the Fortimon3FilterAntiExploitPort communication port to local administrators without additional caller ownership validation. The reviewed 2025.4.30.0 sample accepts a caller-selected process identifier and reaches ZwOpenProcess and ZwTerminateProcess from kernel context, allowing process termination that can impair endpoint defenses. CVE-2026-84386 affects FortiClient for Windows 7.2 and 7.4.0 through 7.4.7; Fortinet recommends upgrading to 7.4.8 or 8.0.0 and later. Product release numbers are distinct from the driver's PE file version. The minifilter must be loaded and its communication port accessible; this is not an unprivileged entry point.

UUID / 70a7693f-2880-47a0-90f2-9703f2b4cab3ADDED / 2026-09-09AUTHOR / Robel Campbell

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

fortimon3.sysSample 1 · HVCI unknown
MD5
e2b86d1430fbb4cdc6d88ad929713d7a
SHA1
f7a69dbb449ca5b965a4ca79f0714b1f4727c527
SHA256
6f131b58dfe47cb7fc721f1023e55242a6f2043fa337467338844fdf338f010f
Imphash
ed630ef1b42d89c4808967f098bf6570
Authentihash MD5
dcc0b464af012965593102fd10f6b041
Authentihash SHA1
e2b50ae6a5ac6195adb6ee1f85c868f424724c0e
Authentihash SHA256
47bf6eb5e5e30b734ad31214fd2c9bd938d129d3bc2a5b055615ed4056222d85
Machine
AMD64
Version
2025.4.30.0
Publisher
Fortinet, Inc.

Research & references

Acknowledgement: Robel Campbell, Halcyon; Mirae Yim @RobelCampbell, @mein-0