Access Control Vulnerability in Fortinet FortiClient Antivirus Drivers
CVE-2015-5737
Currently unrated
Summary
The Fortinet FortiClient Antivirus contains a critical access control vulnerability in specific drivers, namely mdare64_48.sys, mdare32_48.sys, mdare32_52.sys, mdare64_52.sys, and Fortishield.sys. These drivers fail to properly restrict access to APIs managing processes and the Windows registry. As a result, local attackers can exploit this weakness to obtain privileged handles to process identifiers (PIDs). This exploitation may lead to unauthorized access and manipulation of system resources, potentially impacting system integrity and security.
References
Timeline
Vulnerability published
Vulnerability Reserved