PT-2015-2319 · Microsoft · Windows Shell+1
Publicado
2015-10-13
·
Atualizado
2019-05-16
·
CVE-2015-2515
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Shell versions prior to the fixed version
Description
The issue is related to a use-after-free vulnerability in Windows Shell, which allows remote attackers to execute arbitrary code via a crafted toolbar object. This vulnerability can be exploited when Windows Shell improperly handles objects in memory. If successfully exploited, an attacker could cause arbitrary code to execute in the context of the current user, potentially leading to system compromise. The vulnerability requires a user to open a specially crafted toolbar object in Windows for an attack to be successful.
Recommendations
For Windows Shell, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the Windows Shell to minimize the risk of exploitation.
Avoid using specially crafted toolbar objects in Windows until the issue is resolved.
Correção
RCE
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows
Windows Shell