CVE-2015-5736
highCVSS v3 Base Score
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS Score
2.5%
Exploitation probability in 30 days
Top 14% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Confidentiality
C
Integrity
C
Availability
C
Published: September 3, 2015 (3905 days ago)
Last Modified: May 6, 2026
Vendor: Fortinet
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220024 or (2) 0x220028 ioctl call.
CWE
CWE-264Affected Products
fortinet forticlient