Local Memory Exposure in Fortinet FortiClient Software
CVE-2015-4077
Currently unrated
What is CVE-2015-4077?
Fortinet's FortiClient contains vulnerabilities in specific driver files (mdare64_48.sys, mdare32_48.sys, mdare32_52.sys, and mdare64_52.sys) that allow local users to access arbitrary sections of kernel memory through an ioctl call. This exposure can potentially lead to unauthorized access to sensitive information and system instability, heightening the risk of exploitation and compromising the integrity of the affected systems.