PT-2015-3410 · Microsoft · Windows

Published

2015-08-11

·

Updated

2025-04-07

·

CVE-2015-1769

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to the fixed version
Description The issue is related to the Mount Manager component in Microsoft Windows, which mishandles symlinks. This allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device. An attacker who successfully exploits this issue could write a malicious binary to disk and execute it. The exploitation requires the attacker to insert a malicious USB device into a target system.
Recommendations For Microsoft Windows versions prior to the fixed version, to resolve the issue, apply the necessary patch or update to the affected system. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2021-05341
CVE-2015-1769

Affected Products

Windows