CVE-2015-0001Use After Free in Microsoft Windows Server 2012

Severity
1.9LOWNVD
EPSS
0.6%
top 29.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 14

Description

The Windows Error Reporting (WER) component in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to bypass the Protected Process Light protection mechanism and read the contents of arbitrary process-memory locations by leveraging administrative privileges, aka "Windows Error Reporting Security Feature Bypass Vulnerability."

CVSS vector

AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

1
GHSA
GHSA-c73w-5569-h45x: The Windows Error Reporting (WER) component in Microsoft Windows 8, Windows 82022-05-14

💥Exploits & PoCs

1
Exploit-DB
Intermec PM43 Industrial Printer - Local Privilege Escalation2017-03-28

📋Vendor Advisories

23
VMware
VMware ESXi, Fusion, Player, and Workstation updates address important guest privilege escalation vulnerability2016-01-07
VMware
VMware vCenter Server, ESXi, Workstation, Player, and Fusion updates address security issues2015-01-27
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-26
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-26
Red Hat
webkitgtk: use-after-free vulnerability in the handling of input (WSA-2015-0001)2015-01-26

🕵️Threat Intelligence

2
Talos
Microsoft Update Tuesday January 2015: Another Light Month, No IE Bulletins, More Changes to Reporting2015-01-13
Talos
Microsoft Update Tuesday January 2015: Another Light Month, No IE Bulletins, More Changes to Reporting2015-01-13

💬Community

22
Bugzilla
CVE-2015-1779 qemu: vnc: insufficient resource limiting in VNC websockets decoder2015-03-06
Bugzilla
CVE-2014-1308 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-27
Bugzilla
CVE-2014-1303 webkitgtk: heap-based buffer overflow (WSA-2015-0001)2015-01-27
Bugzilla
CVE-2014-1326 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-27
Bugzilla
CVE-2014-1333 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-27