CVE-2015-4077: Infoleak
Published Sep 3, 2015
·Updated
The (1) mdare6448.sys, (2) mdare3248.sys, (3) mdare3252.sys, and (4) mdare6452.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call.
Affected Software
1 affected component
Fortinet Forticlient<=5.2.3
Event History
Sep 3, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4077?
CVE-2015-4077 has been classified as a high severity vulnerability due to its potential for local users to read arbitrary kernel memory.
2
How do I fix CVE-2015-4077?
To fix CVE-2015-4077, upgrade Fortinet FortiClient to version 5.2.4 or later.
3
What systems are affected by CVE-2015-4077?
CVE-2015-4077 affects Fortinet FortiClient versions prior to 5.2.4.
4
What type of vulnerability is CVE-2015-4077?
CVE-2015-4077 is an information exposure vulnerability allowing local users unauthorized access to sensitive kernel memory.
5
Is CVE-2015-4077 exploitable by remote attackers?
No, CVE-2015-4077 is only exploitable by local users with access to the affected system.