CVE-2015-0077: Infoleak
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize function buffers, which allows local users to obtain sensitive information from kernel memory, and possibly bypass the ASLR protection mechanism, via a crafted application, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0077?
CVE-2015-0077 is rated as important due to its potential impact on local users.
How do I fix CVE-2015-0077?
To fix CVE-2015-0077, apply the relevant security update provided by Microsoft for your affected operating system version.
Which versions of Windows are affected by CVE-2015-0077?
CVE-2015-0077 affects Windows Vista SP2, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2003 SP2, Windows Server 2008 SP2, Windows Server 2008 R2 SP1, Windows Server 2012, and Windows RT.
What type of vulnerability is CVE-2015-0077?
CVE-2015-0077 is a local privilege escalation vulnerability caused by improper initialization of function buffers.
Can CVE-2015-0077 be exploited remotely?
No, CVE-2015-0077 requires local access, making it a local only privilege escalation vulnerability.