Lucene search

K
kasperskyKaspersky LabKLA10560
HistoryApr 14, 2015 - 12:00 a.m.

KLA10560 Privilege escalation vulnerability in Microsoft products

2015-04-1400:00:00
Kaspersky Lab
threats.kaspersky.com
38

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

36.3%

An unspecified vulnerability was found in Microsoft products. By exploiting this vulnerability malicious users can gain privileges. This vulnerability can be exploited locally via a specially designed task.

Original advisories

MS15-037

CVE-2015-0098

Related products

Microsoft-Windows-7

Microsoft-Windows-Server-2008

CVE list

CVE-2015-0098 high

KB list

3046269

Solution

Update to the latest version

Impacts

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • Windows 7 x86, x64 Service Pack 1Windows Server 2008 R2 x64, Itanium Service Pack 1

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

36.3%