Access Control Vulnerability in Fortinet FortiClient Antivirus Drivers
CVE-2015-5737

Currently unrated

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
3 September 2015

Summary

The Fortinet FortiClient Antivirus contains a critical access control vulnerability in specific drivers, namely mdare64_48.sys, mdare32_48.sys, mdare32_52.sys, mdare64_52.sys, and Fortishield.sys. These drivers fail to properly restrict access to APIs managing processes and the Windows registry. As a result, local attackers can exploit this weakness to obtain privileged handles to process identifiers (PIDs). This exploitation may lead to unauthorized access and manipulation of system resources, potentially impacting system integrity and security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.