CVE-2015-5736: High severity fortinet forticlient virtual private network vulnerability
Published Sep 3, 2015
·Updated
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220024 or (2) 0x220028 ioctl call.
Affected Software
1 affected component
Fortinet Forticlient<=5.2.3
Event History
Sep 3, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5736?
CVE-2015-5736 is classified as a high severity vulnerability due to its potential for arbitrary code execution with kernel privileges.
2
How do I fix CVE-2015-5736?
The issue can be resolved by upgrading Fortinet FortiClient to version 5.2.4 or later.
3
What does CVE-2015-5736 affect?
CVE-2015-5736 affects Fortinet FortiClient versions prior to 5.2.4.
4
Who can exploit CVE-2015-5736?
Local users with access to the affected system can exploit CVE-2015-5736 to execute arbitrary code.
5
What is the root cause of CVE-2015-5736?
The vulnerability is caused by improper handling of ioctl calls in the Fortishield.sys driver.