Vulnerability Name: CVE-2015-6173 (CCN-108293) Assigned: 2015-12-08 Published: 2015-12-08 Updated: 2019-05-15 Summary: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-6171  and CVE-2015-6174 . CVSS v3 Severity: 8.8 High  (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H  )7.9 High  (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C  )Exploitability Metrics: Attack Vector (AV):  LocalAttack Complexity (AC):  LowPrivileges Required (PR):  LowUser Interaction (UI):  NoneScope: Scope (S):  ChangedImpact Metrics: Confidentiality (C):  HighIntegrity (I):  HighAvailibility (A):  High
CVSS v2 Severity: 7.2 High  (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C  )Exploitability Metrics: Access Vector (AV):  LocalAccess Complexity (AC):  LowAuthentication (Au):  NoneImpact Metrics: Confidentiality (C):  CompleteIntegrity (I):  CompleteAvailibility (A):  Complete
6.8 Medium  (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C  )Exploitability Metrics: Access Vector (AV):  LocalAccess Complexity (AC):  LowAthentication (Au):  Single_InstanceImpact Metrics: Confidentiality (C):  CompleteIntegrity (I):  CompleteAvailibility (A):  Complete
Vulnerability Type: CWE-264 Vulnerability Consequences: Gain Privileges References: Source: MITRE Type: CNACVE-2015-6173  Source: CCN Type: Microsoft Security Bulletin MS15-135Security Update for Windows Kernel Mode Drivers to Address Elevation of Privilege (3119075)  Source: SECTRACK Type: Third Party Advisory, VDB Entry1034334  Source: MS Type: Patch, Vendor AdvisoryMS15-135  Source: XF Type: UNKNOWNms-kernel-cve20156173-priv-esc(108293)  Source: CCN Type: Packet Storm Security [12-18-2015]Win32k Clipboard Bitmap Use-After-Free  Vulnerable Configuration: Configuration 1 :cpe:/o:microsoft:windows_10:-:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:1511:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_7:-:sp1:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_8:-:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_8.1:-:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_rt:-:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*  Configuration CCN 1 :cpe:/o:microsoft:windows_vista:*:sp2:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_vista:*:sp2:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_7:-:sp1:-:*:-:-:x32:*  OR cpe:/o:microsoft:windows_7:*:sp1:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_8:-:-:-:*:-:-:x32:*  OR cpe:/o:microsoft:windows_8:*:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_rt:-:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_8.1:-:-:-:*:-:-:x32:*  OR cpe:/o:microsoft:windows_8.1:*:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_10:-:*:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_10:*:*:*:*:*:*:x64:*    Denotes that component is vulnerable   BACK   
  microsoft  windows 10 -    
microsoft  windows 10 1511    
microsoft  windows 7 - sp1    
microsoft  windows 8 -    
microsoft  windows 8.1 -    
microsoft  windows rt -    
microsoft  windows rt 8.1 -    
microsoft  windows server 2008 - sp2    
microsoft  windows server 2008 r2 sp1    
microsoft  windows server 2008 r2 sp1    
microsoft  windows server 2012 -    
microsoft  windows server 2012 r2    
microsoft  windows vista - sp2    
microsoft  windows vista * sp2    
microsoft  windows server 2008 sp2    
microsoft  windows server 2008 sp2    
microsoft  windows server 2008 
microsoft  windows vista * sp2    
microsoft  windows 7 - sp1    
microsoft  windows 7 * sp1    
microsoft  windows server 2008 r2    
microsoft  windows server 2008 r2    
microsoft  windows 8 - -    
microsoft  windows 8 * 
microsoft  windows server 2012 
microsoft  windows rt - 
microsoft  windows 8.1 - -    
microsoft  windows 8.1 * 
microsoft  windows server 2012 r2    
microsoft  windows rt 8.1 * 
microsoft  windows 10 - 
microsoft  windows 10 *