CVE-2015-0001

Description

The Windows Error Reporting (WER) component in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to bypass the Protected Process Light protection mechanism and read the contents of arbitrary process-memory locations by leveraging administrative privileges, aka Windows Error Reporting Security Feature Bypass Vulnerability.

Risk Information

Base Score
4.4
MODERATE
Vector
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.649

Associated Vulnerability

VulnerabilityOS Platform
ms15-006: vulnerability in windows error reporting could allow security feature bypass: january 13, 2015 for Windows 8 (KB3004365)Windows
ms15-006: vulnerability in windows error reporting could allow security feature bypass: january 13, 2015 for Windows 8.1 (KB3004365)Windows
ms15-006: vulnerability in windows error reporting could allow security feature bypass: january 13, 2015 for Windows 8 for x64-based Systems (KB3004365)Windows
ms15-006: vulnerability in windows error reporting could allow security feature bypass: january 13, 2015 for Windows Server 2012 (KB3004365)Windows
ms15-006: vulnerability in windows error reporting could allow security feature bypass: january 13, 2015 for Windows 8.1 for x64-based Systems (KB3004365)Windows
ms15-006: vulnerability in windows error reporting could allow security feature bypass: january 13, 2015 for Windows Server 2012 R2 (KB3004365)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-16841Security Update for Windows 8 (KB3004365)
PATCH-16842Security Update for Windows 8.1 (KB3004365)
PATCH-16843Security Update for Windows 8 for x64-based Systems (KB3004365)
PATCH-16844Security Update for Windows Server 2012 (KB3004365)
PATCH-16845Security Update for Windows 8.1 for x64-based Systems (KB3004365)
PATCH-16846Security Update for Windows Server 2012 R2 (KB3004365)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234