fortimon3.sys
Fortinet FortiClient's fortimon3.sys minifilter exposes the Fortimon3FilterAntiExploitPort communication port to local administrators without additional caller ownership validation. The reviewed 2025.4.30.0 sample accepts a caller-selected process identifier and reaches ZwOpenProcess and ZwTerminateProcess from kernel context, allowing process termination that can impair endpoint defenses. CVE-2026-84386 affects FortiClient for Windows 7.2 and 7.4.0 through 7.4.7; Fortinet recommends upgrading to 7.4.8 or 8.0.0 and later. Product release numbers are distinct from the driver's PE file version. The minifilter must be loaded and its communication port accessible; this is not an unprivileged entry point.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
fortimon3.sysSample 1 · HVCI unknown
- MD5
e2b86d1430fbb4cdc6d88ad929713d7a- SHA1
f7a69dbb449ca5b965a4ca79f0714b1f4727c527- SHA256
6f131b58dfe47cb7fc721f1023e55242a6f2043fa337467338844fdf338f010f- Imphash
ed630ef1b42d89c4808967f098bf6570- Authentihash MD5
dcc0b464af012965593102fd10f6b041- Authentihash SHA1
e2b50ae6a5ac6195adb6ee1f85c868f424724c0e- Authentihash SHA256
47bf6eb5e5e30b734ad31214fd2c9bd938d129d3bc2a5b055615ed4056222d85- Machine
- AMD64
- Version
- 2025.4.30.0
- Publisher
- Fortinet, Inc.
Research & references
Acknowledgement: Robel Campbell, Halcyon; Mirae Yim @RobelCampbell, @mein-0

