Lucene search

K
cve[email protected]CVE-2015-2416
HistoryJul 14, 2015 - 10:59 p.m.

CVE-2015-2416

2015-07-1422:59:08
CWE-20
web.nvd.nist.gov
32
cve-2015-2416
ole
microsoft
windows
privilege vulnerability
nvd
security
remote attack

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.9 Medium

AI Score

Confidence

Low

0.026 Low

EPSS

Percentile

90.4%

OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted input, as demonstrated by a transition from Low Integrity to Medium Integrity, aka “OLE Elevation of Privilege Vulnerability,” a different vulnerability than CVE-2015-2417.

Affected configurations

NVD
Node
microsoftwindows_2003_serversp2
OR
microsoftwindows_2003_serverMatchr2sp2
OR
microsoftwindows_7Match-sp1
OR
microsoftwindows_8Match-
OR
microsoftwindows_8.1Match-
OR
microsoftwindows_rtMatch-
OR
microsoftwindows_rt_8.1Match-
OR
microsoftwindows_server_2008Match-sp2
OR
microsoftwindows_server_2008Matchr2sp1
OR
microsoftwindows_server_2012Match-
OR
microsoftwindows_server_2012Matchr2datacenter
OR
microsoftwindows_server_2012Matchr2essentials
OR
microsoftwindows_server_2012Matchr2standard
OR
microsoftwindows_vistasp2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.9 Medium

AI Score

Confidence

Low

0.026 Low

EPSS

Percentile

90.4%