A buffer copy without checking size of input vulnerability [CWE-120] in FortiClient Windows may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.
Disable application based filtering in FortiClient EMS VPN configuration:
FortiClient EMS > Remote Access Profile > VPN Tunnel > "Toggle" Application Based
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
