PT-2015-1067 · Microsoft · Windows

Published

2015-04-14

·

Updated

2019-05-14

·

CVE-2015-1644

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to the fixed version
Description The issue is related to improper validation and enforcement of impersonation levels, allowing local users to gain elevated privileges via a crafted application. This could enable an attacker to bypass security checks and acquire administrator credentials, potentially leading to the installation of programs, viewing, changing, or deleting data, and creating new accounts with full administrative rights. An estimated number of potentially affected devices is not provided.
Recommendations For Microsoft Windows versions prior to the fixed version, consider restricting access to sensitive areas of the system to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider disabling any features that rely on impersonation levels until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09927
CVE-2015-1644

Affected Products

Windows