CVE-2015-2549Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Windows Server 2008

Severity
7.2HIGHNVD
EPSS
1.5%
top 18.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateMay 14

Description

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-7g5r-xg7q-hxgf: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 82022-05-14

🕵️Threat Intelligence

3
Talos
Microsoft Patch Tuesday - October 20152015-10-13
Talos
Microsoft Patch Tuesday - October 20152015-10-13
Zscaler
Zscaler detects IE & MS Office Vulnerabilities | 10-13-2015

💬Community

6
Bugzilla
CVE-2015-7497 libxml2: Heap-based buffer overflow in xmlDictComputeFastQKey2015-11-13
Bugzilla
CVE-2015-7498 libxml2: Heap-based buffer overflow in xmlParseXmlDecl2015-11-13
Bugzilla
CVE-2015-7500 libxml2: Heap buffer overflow in xmlParseMisc2015-11-13
Bugzilla
CVE-2015-7499 libxml2: Heap-based buffer overflow in xmlGROW2015-11-13
Bugzilla
libxml2: Multiple out-of-bounds reads in xmlDictComputeFastKey.isra.2 and xmlDictAddString.isra.O2015-11-13