CVE-2015-5737 describes a privilege escalation vulnerability affecting Fortinet FortiClient versions prior to 5.2.4. Specifically, certain FortiClient drivers (mdare64_48.sys, mdare32_48.sys, mdare32_52.sys, mdare64_52.sys, and Fortishield.sys) inadequately restrict access to their management APIs. This flaw allows a local attacker to gain a privileged handle to a process ID (PID) and potentially achieve other unspecified impacts, as demonstrated by a specific ioctl call. The vulnerability carries a CVSS score of 7.2, indicating high severity. Its attack vector is local (AV:L) with low attack complexity (AC:L), requiring no authentication (Au:N). The potential impact includes complete compromise of confidentiality, integrity, and availability (C:C/I:C/A:C). There is no evidence of active exploitation in the wild, and it is not listed in the CISA KEV catalog. No public exploit code or Metasploit modules are available, and there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.2.3CPE matchmatch criteria | cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.