Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2015-6102Sensitive Information Exposure in Microsoft Windows 10

Severity
2.1LOWNVD
EPSS
3.8%
top 11.87%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 11
Latest updateMay 14

Description

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via a crafted application, aka "Windows Kernel Memory Information Disclosure Vulnerability."

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-j8xv-9pjh-mqw5: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 82022-05-14

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows - Cursor Object Memory Leak (MS15-115)2015-11-23

🕵️Threat Intelligence

3
Talos
Microsoft Patch Tuesday - November 20152015-11-10
Talos
Microsoft Patch Tuesday - November 20152015-11-10
Zscaler
Zscaler detects IE & MS Office Vulnerabilities | 11-10-2015