PT-2015-3410 · Microsoft · Windows
Published
2015-08-11
·
Updated
2025-04-07
·
CVE-2015-1769
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fixed version
Description
The issue is related to the Mount Manager component in Microsoft Windows, which mishandles symlinks. This allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device. An attacker who successfully exploits this issue could write a malicious binary to disk and execute it. The exploitation requires the attacker to insert a malicious USB device into a target system.
Recommendations
For Microsoft Windows versions prior to the fixed version, to resolve the issue, apply the necessary patch or update to the affected system.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows