CVE-2015-0010: Low severity microsoft windows 7 vulnerability
The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1, when the CRYPTPROTECTMEMORYSAMELOGON option is used, does not check an impersonation token's level, which allows local users to bypass intended decryption restrictions by leveraging a service that (1) has a named-pipe planting vulnerability or (2) uses world-readable shared memory for encrypted data, aka "CNG Security Feature Bypass Vulnerability" or MSRC ID 20707.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0010?
CVE-2015-0010 has a severity rating of important as it could allow an attacker to access sensitive information.
How do I fix CVE-2015-0010?
To fix CVE-2015-0010, it is recommended to apply the security updates provided by Microsoft for the affected versions.
Which Microsoft Windows versions are affected by CVE-2015-0010?
CVE-2015-0010 affects Microsoft Windows 7, Windows Vista, Windows Server 2003, and various other versions of Windows up to Server 2012 R2.
What type of vulnerability is CVE-2015-0010?
CVE-2015-0010 is a cryptographic vulnerability found in the CryptProtectMemory function of the Windows operating system.
Can CVE-2015-0010 be exploited remotely?
Exploitation of CVE-2015-0010 typically requires local access to the system, rather than being a remote exploit.