Microsoft Windows FAT32 Disk Partition Driver CVE-2014-4115 Local Privilege Escalation Vulnerability
BID:70343
Info
Microsoft Windows FAT32 Disk Partition Driver CVE-2014-4115 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 70343 |
| Class: | Design Error |
| CVE: |
CVE-2014-4115 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 14 2014 12:00AM |
| Updated: | Oct 21 2014 12:02AM |
| Credit: | Marcin 'Icewall' Noga of Cisco Talos |
| Vulnerable: |
Microsoft Windows Vista x64 Edition SP2 Microsoft Windows Vista SP2 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 SP2 Avaya Messaging Application Server 5.2 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows FAT32 Disk Partition Driver CVE-2014-4115 Local Privilege Escalation Vulnerability
Microsoft Windows FAT32 Disk Partition Driver is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary code with elevated privileges. Successful exploits will result in the complete compromise of affected computers.
Microsoft Windows FAT32 Disk Partition Driver is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary code with elevated privileges. Successful exploits will result in the complete compromise of affected computers.
Exploit / POC
Microsoft Windows FAT32 Disk Partition Driver CVE-2014-4115 Local Privilege Escalation Vulnerability
An attacker requires physical access to the system to exploit the issue.
An attacker requires physical access to the system to exploit the issue.
Solution / Fix
Microsoft Windows FAT32 Disk Partition Driver CVE-2014-4115 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Windows FAT32 Disk Partition Driver CVE-2014-4115 Local Privilege Escalation Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)