FortiClient Antivirus information leakage (CVE-2015-4077)
FortiClient Antivirus information leakage (CVE-2015-4077)
Release date:
Updated on: 2015-09-02
Affected Systems:
FortiGuard forticlient 5.2.4
Description:
CVE (CAN) ID: CVE-2015-4077
FortiClient is a client-based software solution that provides a series of security functions for desktops and laptops.
FortiClient's "mdare64_48.sys", "mdare32_48.sys", "mdare32_52.sys", "mdare64_52.sys" driver has a security vulnerability. Attackers can read arbitrary kernel memory through some parameters of IOCTL 0x22608C.
<* Source: Enrique Nissim
*>
Suggestion:
Vendor patch:
FortiGuard
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.forticlient.com /.
Http://docs.fortinet.com/d/forticlient-5.2.4-windows-release-notes.pdf.
This article permanently updates the link address: