CVE-2015-2454Improper Access Control in Microsoft Windows Server 2008

Severity
2.1LOWNVD
EPSS
1.0%
top 23.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 15
Latest updateMay 14

Description

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows KMD Security Feature Bypass Vulnerability."

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-jrc5-254w-5vfw: The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 82022-05-14

📋Vendor Advisories

14
Red Hat
chromium-browser: Cross-origin bypass in V82015-09-24
Red Hat
chromium-browser: Cross-origin bypass in DOM2015-09-24
Red Hat
chromium-browser: Use-after-free in Blink2015-09-01
Red Hat
chromium-browser: Use-after-free in Printing2015-09-01
Red Hat
chromium-browser: various fixes from internal audits2015-09-01

💬Community

2
Bugzilla
CVE-2015-1302 chromium-browser: information leak in PDF viewer2015-11-11
Bugzilla
CVE-2015-6581 openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd2015-10-01