First published: Sat Aug 15 2015(Updated: )
The Windows shell in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Shell Security Feature Bypass Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.0 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Vista | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2465 is rated as important by Microsoft, indicating that it could allow local privilege escalation.
To fix CVE-2015-2465, install the latest security updates provided by Microsoft for affected Windows versions.
CVE-2015-2465 affects Windows Vista SP2, Windows 7 SP1, Windows 8, Windows 8.1, Windows 10, and various Windows Server editions.
CVE-2015-2465 can be exploited through local user impersonation, allowing privilege escalation on the affected systems.
There are no known workarounds for CVE-2015-2465, and applying the security update is the recommended mitigation.