PT-2015-2673 · Microsoft · Windows 10+8

Published

2015-11-10

·

Updated

2019-05-16

·

CVE-2015-6113

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Windows Vista SP2 Windows Server 2008 SP2 and R2 SP1 Windows 7 SP1 Windows 8 Windows 8.1 Windows Server 2012 Gold and R2 Windows RT Gold and 8.1 Windows 10 Gold and 1511
Description The issue allows local users to bypass intended filesystem permissions by leveraging Low Integrity access. This is due to errors in security settings. An attacker could potentially modify files outside a low integrity level application by running a specially crafted application on an affected system.
Recommendations For Windows Vista SP2, update the system to address the security feature bypass vulnerability. For Windows Server 2008 SP2 and R2 SP1, apply the necessary security patches to resolve the issue. For Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511, ensure that all security updates are installed to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to low integrity level applications to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-12038
CVE-2015-6113

Affected Products

Windows
Windows 10
Windows 7
Windows 8
Windows 8.1
Windows Rt
Windows Server 2008
Windows Server 2012
Windows Vista