CVE-2015-2473Microsoft Windows Server 2008 vulnerability

4 documents3 sources
Severity
9.3CRITICALNVD
EPSS
31.8%
top 3.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 15
Latest updateMay 14

Description

Untrusted search path vulnerability in the client in Remote Desktop Protocol (RDP) through 8.1 in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rdp file, aka "Remote Desktop Protocol DLL Planting Remote Code Execution Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

1
GHSA
GHSA-p9g2-7xrp-3pjg: Untrusted search path vulnerability in the client in Remote Desktop Protocol (RDP) through 82022-05-14

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday - August 20152015-08-11
Talos
Microsoft Patch Tuesday - August 20152015-08-11