Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
CVE-2015-0062
CVE information
Published
Last Modified
CVSSv2.0 Severity
Impact Analysis
Description
Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privileges via a crafted application that leverages incorrect impersonation handling in a process that uses the SeAssignPrimaryTokenPrivilege privilege, aka "Windows Create Process Elevation of Privilege Vulnerability.".
CVSSv2.0 Score
- Severity
- High
- Base Score
- 7.2/10
- Exploit Score
- 3.9/10
- Access Vector
- Local
- Access Complexity
- Low
- Authentication Required
- None
- Impact Score
- 10/10
- Confidentiality Impact
- Complete
- Availability Impact
- Complete
- Integrity Impact
- Complete
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* |
Yes
|
- | - | |
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itani |
Yes
|
- | - | |
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* |
Yes
|
- | - |
References
- http://www.securityfocus.com/bid/72458
- http://www.securitytracker.com/id/1031724
- http://secunia.com/advisories/62840
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100438
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100437
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-015