CVE-2015-4077
FortiClient < 5.2.3 - Unauthorized Kernel Memory Read via mdare Driver ioctl
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2015-4077. PoCs published by sickness & mschenk, ApexPredator-InfoSec.
AI-analyzed exploit summary This exploit targets CVE-2015-5736, a privilege escalation vulnerability in FortiShield.sys. It leverages memory leaks and ROP chains to achieve arbitrary code execution in kernel mode, ultimately spawning a command prompt with elevated privileges.
Description
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call.
Exploits (2)
This exploit targets CVE-2015-5736, a privilege escalation vulnerability in FortiShield.sys. It leverages memory leaks and ROP chains to achieve arbitrary code execution in kernel mode, ultimately spawning a command prompt with elevated privileges.
This repository contains a combined proof-of-concept exploit for CVE-2021-31955, CVE-2015-4077, and CVE-2015-5736, targeting Windows 10 20H2. It leverages memory corruption and privilege escalation techniques to achieve local privilege escalation (LPE).