CVE-2015-0016: Microsoft Windows TS WebProxy Directory Traversal Vulnerability
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Directory Traversal Elevation of Privilege Vulnerability."
Other sources
Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0016?
CVE-2015-0016 is rated as a high severity vulnerability that allows remote attackers to gain elevated privileges.
How do I fix CVE-2015-0016?
To fix CVE-2015-0016, ensure that you apply the latest security updates provided by Microsoft for your affected operating system.
What systems are affected by CVE-2015-0016?
CVE-2015-0016 affects Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 and R2, and Windows RT.
What type of vulnerability is CVE-2015-0016?
CVE-2015-0016 is classified as a directory traversal vulnerability in the TS WebProxy component.
Can CVE-2015-0016 be exploited remotely?
Yes, CVE-2015-0016 can be exploited remotely by attackers to elevate their privileges on the affected systems.