CVE-2015-4077

FortiClient < 5.2.3 - Unauthorized Kernel Memory Read via mdare Driver ioctl

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2015-4077. PoCs published by sickness & mschenk, ApexPredator-InfoSec.

AI-analyzed exploit summary This exploit targets CVE-2015-5736, a privilege escalation vulnerability in FortiShield.sys. It leverages memory leaks and ROP chains to achieve arbitrary code execution in kernel mode, ultimately spawning a command prompt with elevated privileges.

Description

The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call.

Exploits (2)

exploitdb WORKING POC VERIFIED
by sickness & mschenk · c++localwindows_x86-64
https://www.exploit-db.com/exploits/45149

This exploit targets CVE-2015-5736, a privilege escalation vulnerability in FortiShield.sys. It leverages memory leaks and ROP chains to achieve arbitrary code execution in kernel mode, ultimately spawning a command prompt with elevated privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: FortiShield.sys (Fortinet FortiClient)
No auth needed
Prerequisites: Access to the vulnerable system · Presence of FortiShield.sys driver · Ability to interact with the driver via DeviceIoControl
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by ApexPredator-InfoSec · poc
https://github.com/ApexPredator-InfoSec/forti_shield

This repository contains a combined proof-of-concept exploit for CVE-2021-31955, CVE-2015-4077, and CVE-2015-5736, targeting Windows 10 20H2. It leverages memory corruption and privilege escalation techniques to achieve local privilege escalation (LPE).

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Windows 10 20H2
No auth needed
Prerequisites: Windows 10 20H2 environment · Vulnerable driver or kernel component
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45149/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033439
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/536369/100/0/threaded
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Sep/0

Scores

EPSS 0.0017
EPSS Percentile 38.9%

Details

CWE
CWE-200
Status published
Products (1)
fortinet/forticlient < 5.2.3
Published Sep 03, 2015
Tracked Since Feb 18, 2026