CVE-2014-0315: Medium severity Microsoft Windows 7 vulnerability
Untrusted search path vulnerability in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse cmd.exe file in the current working directory, as demonstrated by a directory that contains a .bat or .cmd file, aka "Windows File Handling Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0315?
CVE-2014-0315 is rated as important, indicating a moderate risk of exploitation.
How do I fix CVE-2014-0315?
To fix CVE-2014-0315, apply the security updates provided in the Microsoft Security Bulletin MS14-019.
What systems are affected by CVE-2014-0315?
CVE-2014-0315 affects various versions of Microsoft Windows, including Windows XP SP2/SP3, Windows 7 SP1, and Windows Server 2003 SP2.
Can CVE-2014-0315 be exploited locally?
Yes, CVE-2014-0315 can be exploited by local users to gain elevated privileges.
What type of vulnerability is CVE-2014-0315?
CVE-2014-0315 is classified as an untrusted search path vulnerability.