PT-2015-2319 · Microsoft · Windows Shell+1

Published

2015-10-13

·

Updated

2019-05-16

·

CVE-2015-2515

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Shell versions prior to the fixed version
Description The issue is related to a use-after-free vulnerability in Windows Shell, which allows remote attackers to execute arbitrary code via a crafted toolbar object. This vulnerability can be exploited when Windows Shell improperly handles objects in memory. If successfully exploited, an attacker could cause arbitrary code to execute in the context of the current user, potentially leading to system compromise. The vulnerability requires a user to open a specially crafted toolbar object in Windows for an attack to be successful.
Recommendations For Windows Shell, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Windows Shell to minimize the risk of exploitation. Avoid using specially crafted toolbar objects in Windows until the issue is resolved.

Fix

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11684
CVE-2015-2515

Affected Products

Windows
Windows Shell