CVE-2015-4077 describes a local information disclosure vulnerability affecting specific Fortinet FortiClient drivers (mdare64_48.sys, mdare32_48.sys, mdare32_52.sys, and mdare64_52.sys) prior to version 5.2.4. An attacker with local access could exploit this flaw by making a crafted ioctl call (0x22608C) to read arbitrary kernel memory. Rated with a CVSS score of 2.1, this vulnerability has low attack complexity and requires local access, with the primary impact being confidentiality (disclosure of kernel memory). While not observed in active exploitation and not listed in CISA's KEV catalog, an ExploitDB entry (EDB-45149) exists, indicating public exploit code for local privilege escalation, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.2.3CPE matchmatch criteria | cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.