Forticlient – A vulnerability in the software drivers exposed users' computers to risk
FortiClient, a client-level security solution that offers broad protection to computers, has fixed a privilege escalation bug that allowed unauthorized users to gain system-level privileges.
The vulnerability (CORE-2015-0013) was discovered by researchers at Core Security and affects version 5.2.3 of the antivirus software, as well as all previous versions.
According to Fortinet's security team, the vulnerability was disclosed in June, and was patched with the release of version 5.2.4 in early September.
The problem lies in four drivers (“mdare64_48.sys”, “mdare32_48.sys”, “mdare32_52.sys,” and “mdare64_52.sys”), which, when receiving commands from system calls (IOCTL System Calls), with specific parameters, can allow an unprivileged user to assume system-level privileges.
This could allow an attacker who had previously infected the system to use the FortiClient antivirus vulnerability to take control of a vulnerable Windows computer. The attacker would then be able to infect the system with malware, extract personal data and send it to a C&C server, or use the computer for various other illegal activities.
