sickness & mschenk

2 exploits Active since Sep 2015
CVE-2015-4077 EXPLOITDB c++ WORKING POC
FortiClient < 5.2.3 - Unauthorized Kernel Memory Read via mdare Driver ioctl
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call.
CVE-2015-5736 EXPLOITDB c++ WORKING POC
Fortinet FortiClient < 5.2.3 - Local Privilege Escalation via Fortishield.sys Ioctl Calls
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220024 or (2) 0x220028 ioctl call.