Lucene search

K
cve[email protected]CVE-2015-2368
HistoryJul 14, 2015 - 9:59 p.m.

CVE-2015-2368

2015-07-1421:59:05
web.nvd.nist.gov
45
cve-2015-2368
microsoft
windows
untrusted search path vulnerability
remote code execution

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7 High

AI Score

Confidence

Low

0.033 Low

EPSS

Percentile

91.4%

Untrusted search path vulnerability in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka “Windows DLL Remote Code Execution Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_7Match-sp1
OR
microsoftwindows_8.1Match-
OR
microsoftwindows_rt_8.1Match-
OR
microsoftwindows_server_2008Matchr2sp1
OR
microsoftwindows_server_2012Matchr2datacenter
OR
microsoftwindows_server_2012Matchr2essentials
OR
microsoftwindows_server_2012Matchr2standard

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7 High

AI Score

Confidence

Low

0.033 Low

EPSS

Percentile

91.4%