PT-2015-2319 · Microsoft · Windows Shell+1

Publicado

2015-10-13

·

Atualizado

2019-05-16

·

CVE-2015-2515

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Shell versions prior to the fixed version
Description The issue is related to a use-after-free vulnerability in Windows Shell, which allows remote attackers to execute arbitrary code via a crafted toolbar object. This vulnerability can be exploited when Windows Shell improperly handles objects in memory. If successfully exploited, an attacker could cause arbitrary code to execute in the context of the current user, potentially leading to system compromise. The vulnerability requires a user to open a specially crafted toolbar object in Windows for an attack to be successful.
Recommendations For Windows Shell, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Windows Shell to minimize the risk of exploitation. Avoid using specially crafted toolbar objects in Windows until the issue is resolved.

Correção

RCE

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11684
CVE-2015-2515

Produtos afetados

Windows
Windows Shell