PT-2015-5750 · Microsoft · Windows
Published
2015-08-11
·
Updated
2019-05-14
·
CVE-2015-2454
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fixed version
Description
A security feature bypass issue exists due to the kernel-mode driver's failure to properly validate and enforce impersonation levels. This allows local users to gain privileges via a crafted application. An attacker who successfully exploits this issue could bypass impersonation-level security and gain elevated privileges on a targeted system. The issue by itself does not allow arbitrary code execution, but it could be used in conjunction with another issue. To exploit this, an attacker would have to log on to an affected system.
Recommendations
For Microsoft Windows versions prior to the fixed version, update to the latest version to resolve the issue.
As a temporary workaround, consider restricting access to sensitive resources to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows