CVE-2015-5736 describes a local privilege escalation vulnerability in the Fortishield.sys driver of Fortinet FortiClient versions prior to 5.2.4. An authenticated local attacker can execute arbitrary code with kernel privileges by manipulating callback functions via specific ioctl calls. This vulnerability has a CVSS score of 7.2, indicating high severity with complete confidentiality, integrity, and availability impacts. While not listed in CISA's KEV catalog, multiple public exploits exist on ExploitDB, demonstrating its exploitability. There is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.2.3CPE matchmatch criteria | cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.