CVE-2015-5736: Fortinet FortiClient

High severity, CVSS 7.2. EPSS: 2% chance of exploitation in the next 30 days.

The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220024 or (2) 0x220028 ioctl call.

Affected products

  • Fortinet FortiClient: up to and including 5.2.3

Published 2015-09-03. Last modified 2026-06-17.