PT-2015-2319 · Microsoft · Windows Shell+1
Published
2015-10-13
·
Updated
2019-05-16
·
CVE-2015-2515
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Shell versions prior to the fixed version
Description
The issue is related to a use-after-free vulnerability in Windows Shell, which allows remote attackers to execute arbitrary code via a crafted toolbar object. This vulnerability can be exploited when Windows Shell improperly handles objects in memory. If successfully exploited, an attacker could cause arbitrary code to execute in the context of the current user, potentially leading to system compromise. The vulnerability requires a user to open a specially crafted toolbar object in Windows for an attack to be successful.
Recommendations
For Windows Shell, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the Windows Shell to minimize the risk of exploitation.
Avoid using specially crafted toolbar objects in Windows until the issue is resolved.
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Shell