CVE-2014-2780Microsoft Windows Server 2008 vulnerability

CWE-2645 documents3 sources
Severity
6.9MEDIUMNVD
EPSS
3.1%
top 13.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 8
Latest updateMay 14

Description

DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to gain privileges by leveraging control over a low-integrity process to execute a crafted application, aka "DirectShow Elevation of Privilege Vulnerability."

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-62ff-rg8c-pq4j: DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 82022-05-14

🕵️Threat Intelligence

3
Talos
Microsoft Update Tuesday August 2014: Media Center and Internet Explorer2014-08-12
Talos
Microsoft Update Tuesday August 2014: Media Center and Internet Explorer2014-08-12
Talos
Microsoft Update Tuesday July 2014: light month, mostly Internet Explorer2014-07-08