Vulnerability Name: | CVE-2015-0002 (CCN-99523) | ||||||||
Assigned: | 2014-11-18 | ||||||||
Published: | 2015-01-13 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify that an impersonation token is associated with an administrative account, which allows local users to gain privileges by running AppCompatCache.exe with a crafted DLL file, aka MSRC ID 20544 or "Microsoft Application Compatibility Infrastructure Elevation of Privilege Vulnerability." | ||||||||
CVSS v3 Severity: | 4.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.9 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
3.3 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:P/I:P/A:P/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-0002 Source: SECUNIA Type: UNKNOWN 61277 Source: CCN Type: Microsoft Security Bulletin MS15-001 Vulnerability in Windows Application Compatibility Cache could allow Elevation of Privilege (3023266) Source: CCN Type: Microsoft Security Bulletin MS16-048 Security Update for CSRSS (3148528) Source: MISC Type: UNKNOWN http://twitter.com/sambowne/statuses/550384131683520512 Source: BID Type: UNKNOWN 71972 Source: CCN Type: BID-71972 Microsoft Windows CVE-2015-0002 Local Privilege Escalation Vulnerability Source: MISC Type: UNKNOWN http://www.zdnet.com/article/google-discloses-unpatched-windows-vulnerability/ Source: MISC Type: Exploit https://code.google.com/p/google-security-research/issues/detail?id=118 Source: MS Type: UNKNOWN MS15-001 Source: XF Type: UNKNOWN ms-appcompatcache-cve20150002-priv-esc(99523) Source: XF Type: UNKNOWN ms-appcompatcache-cve20150002-priv-esc(99523) Source: XF Type: UNKNOWN win-ms15kb3023266-update(99524) Source: CCN Type: Packet Storm Security [01-15-2015] Microsoft Windows NtApphelpCacheControl Improper Authorization Check | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |