PT-2015-2007 · Microsoft · Windows 10+5
Publicado
2015-09-08
·
Atualizado
2020-09-08
·
CVE-2015-2528
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions 8 through 10
Windows Server 2012 Gold and R2
Windows RT Gold and 8.1
Description
The issue arises due to insufficient validation of input data, allowing a local attacker to gain elevated privileges via a crafted application. An attacker must first log on to the system to exploit this issue. There is no information provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations
For Windows 8, update to a version that properly constrains impersonation levels.
For Windows 8.1, apply the necessary patch to enforce impersonation-level security checks.
For Windows Server 2012 Gold and R2, restrict access to sensitive areas of the system until a patch is available.
For Windows RT Gold and 8.1, consider disabling any applications that may be used to exploit this issue until a fix is released.
For Windows 10, ensure that all security updates are applied to prevent exploitation.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Windows
Windows 10
Windows 8
Windows 8.1
Windows Rt
Windows Server 2012