Lucene search

K
kasperskyKaspersky LabKLA10473
HistoryMar 10, 2015 - 12:00 a.m.

KLA10473 Code execution vulnerability in Microsoft products

2015-03-1000:00:00
Kaspersky Lab
threats.kaspersky.com
539

8.3 High

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.311 Low

EPSS

Percentile

97.0%

Lack of authentication control was found in Microsoft products. By exploiting this vulnerability malicious users execute arbitrary code. This vulnerability can be exploited remotely via a specially designed UNC share.

Original advisories

MS advisory

CVE-2015-0008

Related products

Microsoft-Windows-Vista-4

Microsoft-Windows-Server-2012

Microsoft-Windows-8

Microsoft-Windows-7

Microsoft-Windows-Server-2008

Microsoft-Windows-Server-2003

Windows-RT

CVE list

CVE-2015-0008 critical

KB list

3000483

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • Windows Server 2003 x86, x64, Itanium-based Service Pack 2Windows Vista x86, x64 Service Pack 2Windows Server 2008 x86, x64, Itanium-based Service Pack 2Windows 7 x86, x64 service Pack 1Windows Server 2008 R2 x64, Itanium-based Service Pack 1Windows 8 x86, x64Windows 8.1 x86, x64Windows Server 2012Windows Server 2012 R2Windows RTWindows RT 8.1

8.3 High

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.311 Low

EPSS

Percentile

97.0%