Microsoft Windows CVE-2015-0062 Local Privilege Escalation Vulnerability
BID:72458
Info
Microsoft Windows CVE-2015-0062 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 72458 |
| Class: | Unknown |
| CVE: |
CVE-2015-0062 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 10 2015 12:00AM |
| Updated: | May 12 2015 07:46PM |
| Credit: | James Forshaw of Google Project Zero |
| Vulnerable: |
Microsoft Windows Server 2008 R2 Itanium SP1 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for 32-bit Systems SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Windows CVE-2015-0062 Local Privilege Escalation Vulnerability
Microsoft Windows is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges within the context of the application.
Microsoft Windows is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges within the context of the application.
Exploit / POC
Microsoft Windows CVE-2015-0062 Local Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Windows CVE-2015-0062 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft Windows 8.1 for x64-based Systems 0
Microsoft Windows 8 for 32-bit Systems 0
Microsoft Windows 7 for 32-bit Systems SP1
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
Microsoft Windows 7 for x64-based Systems SP1
Microsoft Windows Server 2012 0
Microsoft Windows 8 for x64-based Systems 0
Microsoft Windows Server 2012 R2 0
Microsoft Windows 8.1 for 32-bit Systems 0
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft Windows 8.1 for x64-based Systems 0
-
Microsoft Security Update for Windows 8.1 for x64-based Systems (KB3031432)
http://www.microsoft.com/downloads/details.aspx?familyid=1252B289-EBAE -47D4-A3C8-3E65D3A83E67
Microsoft Windows 8 for 32-bit Systems 0
-
Microsoft Security Update for Windows 8 (KB3031432)
http://www.microsoft.com/downloads/details.aspx?familyid=B3FDBF99-7244 -4EAA-A061-5D2FA3C99158
Microsoft Windows 7 for 32-bit Systems SP1
-
Microsoft Security Update for Windows 7 (KB3031432)
http://www.microsoft.com/downloads/details.aspx?familyid=49ABDFDD-E4E4 -41D2-B010-AD2CFDE79628
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB3031432)
http://www.microsoft.com/downloads/details.aspx?familyid=6426FD13-0D46 -4009-8E0D-F2D5C27F4AC7
Microsoft Windows 7 for x64-based Systems SP1
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB3031432)
http://www.microsoft.com/downloads/details.aspx?familyid=2E2FA7D1-D6C2 -44DA-A119-6DEF1028CF77
Microsoft Windows Server 2012 0
-
Microsoft Security Update for Windows Server 2012 (KB3031432)
http://www.microsoft.com/downloads/details.aspx?familyid=9A4C61FD-005E -448E-80AA-D705AF0468A9
Microsoft Windows 8 for x64-based Systems 0
-
Microsoft Security Update for Windows 8 for x64-based Systems (KB3031432)
http://www.microsoft.com/downloads/details.aspx?familyid=566BA0D1-746E -464A-BA86-0500B167A9A9
Microsoft Windows Server 2012 R2 0
-
Microsoft Security Update for Windows Server 2012 R2 (KB3031432)
http://www.microsoft.com/downloads/details.aspx?familyid=01BA2D3B-6E21 -4B13-A59D-7AA29BA2D79C
Microsoft Windows 8.1 for 32-bit Systems 0
-
Microsoft Security Update for Windows 8.1 (KB3031432)
http://www.microsoft.com/downloads/details.aspx?familyid=4AA86E66-4013 -4B8B-B424-7306AC890C2A
References
Microsoft Windows CVE-2015-0062 Local Privilege Escalation Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)