Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2015-6098Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Windows Server 2008

Severity
7.2HIGHNVD
EPSS
4.5%
top 10.83%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 11
Latest updateMay 14

Description

Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows NDIS Elevation of Privilege Vulnerability."

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

1
GHSA
GHSA-7c4h-9cr7-4q47: Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and2022-05-14

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows - 'ndis.sys' IOCTL 0x170034 (ndis!ndisNsiGetIfNameForIfIndex) Pool Buffer Overflow (MS15-117)2015-11-23

🕵️Threat Intelligence

3
Talos
Microsoft Patch Tuesday - November 20152015-11-10
Talos
Microsoft Patch Tuesday - November 20152015-11-10
Zscaler
Zscaler detects IE & MS Office Vulnerabilities | 11-10-2015