CVE-2015-5737
Status: ModifiedHigh (7.2)—
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, (4) mdare64_52.sys, and (5) Fortishield.sys drivers in Fortinet FortiClient before 5.2.4 do not properly restrict access to the API for management of processes and the Windows registry, which allows local users to obtain a privileged handle to a PID and possibly have unspecified other impact, as demonstrated by a 0x2220c8 ioctl call.
CVSS
- Version: 2.0
- Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
- Base score: 7.2
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.52%
- Percentile among all scored CVEs: 42
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-264
References
- http://fortiguard.com/advisory/mulitple-vulnerabilities-in-forticlient
- http://packetstormsecurity.com/files/133398/FortiClient-Antivirus-Information-Exposure-Access-Control.html
- http://seclists.org/fulldisclosure/2015/Sep/0
- http://www.coresecurity.com/advisories/forticlient-antivirus-multiple-vulnerabilities
- http://www.fortiguard.com/advisory/mulitple-vulnerabilities-in-forticlient
- http://www.securityfocus.com/archive/1/536369/100/0/threaded
- http://www.securitytracker.com/id/1033439
- http://fortiguard.com/advisory/mulitple-vulnerabilities-in-forticlient
- http://packetstormsecurity.com/files/133398/FortiClient-Antivirus-Information-Exposure-Access-Control.html
- http://seclists.org/fulldisclosure/2015/Sep/0
- http://www.coresecurity.com/advisories/forticlient-antivirus-multiple-vulnerabilities
- http://www.fortiguard.com/advisory/mulitple-vulnerabilities-in-forticlient
- http://www.securityfocus.com/archive/1/536369/100/0/threaded
- http://www.securitytracker.com/id/1033439
Raw JSON (NVD)
Show
{
"id": "CVE-2015-5737",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-09-03T14:59:07.680",
"references": [
{
"url": "http://fortiguard.com/advisory/mulitple-vulnerabilities-in-forticlient",
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/133398/FortiClient-Antivirus-Information-Exposure-Access-Control.html",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2015/Sep/0",
"source": "cve@mitre.org"
},
{
"url": "http://www.coresecurity.com/advisories/forticlient-antivirus-multiple-vulnerabilities",
"source": "cve@mitre.org"
},
{
"url": "http://www.fortiguard.com/advisory/mulitple-vulnerabilities-in-forticlient",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/536369/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id/1033439",
"source": "cve@mitre.org"
},
{
"url": "http://fortiguard.com/advisory/mulitple-vulnerabilities-in-forticlient",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/133398/FortiClient-Antivirus-Information-Exposure-Access-Control.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2015/Sep/0",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.coresecurity.com/advisories/forticlient-antivirus-multiple-vulnerabilities",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.fortiguard.com/advisory/mulitple-vulnerabilities-in-forticlient",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/536369/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1033439",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, (4) mdare64_52.sys, and (5) Fortishield.sys drivers in Fortinet FortiClient before 5.2.4 do not properly restrict access to the API for management of processes and the Windows registry, which allows local users to obtain a privileged handle to a PID and possibly have unspecified other impact, as demonstrated by a 0x2220c8 ioctl call."
},
{
"lang": "es",
"value": "Vulnerabilidad en los drivers (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, (4) mdare64_52.sys y (5) Fortishield.sys en Fortinet FortiClient en versiones anteriores a 5.2.4, no restringe adecuadamente el acceso a la API para la gestión de procesos y el registro de Windows, lo que permite a usuarios locales obtener un identificador con privilegios a un PID y posiblemente tener otro impacto no especificado, como se demuestra por una llamada ioctl en 0x2220c8."
}
],
"lastModified": "2026-06-17T00:29:41.047",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7123E6A7-54BE-4406-9B1A-EF3E5B367601",
"versionEndIncluding": "5.2.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}