CVE-2015-2509

Description

Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Media Center link (mcl) file, aka Windows Media Center RCE Vulnerability.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
87.937

Associated Vulnerability

VulnerabilityOS Platform
ms15-100: vulnerability in windows media center could allow remote code execution: september 8, 2015 for Windows Vista (KB3087918)Windows
ms15-100: vulnerability in windows media center could allow remote code execution: september 8, 2015 for Windows 7 (KB3087918)Windows
ms15-100: vulnerability in windows media center could allow remote code execution: september 8, 2015 for Windows 8 (KB3087918)Windows
ms15-100: vulnerability in windows media center could allow remote code execution: september 8, 2015 for Windows 8.1 (KB3087918)Windows
ms15-100: vulnerability in windows media center could allow remote code execution: september 8, 2015 for Windows Vista for x64-based Systems (KB3087918)Windows
ms15-100: vulnerability in windows media center could allow remote code execution: september 8, 2015 for Windows 7 for x64-based Systems (KB3087918)Windows
ms15-100: vulnerability in windows media center could allow remote code execution: september 8, 2015 for Windows 8 for x64-based Systems (KB3087918)Windows
ms15-100: vulnerability in windows media center could allow remote code execution: september 8, 2015 for Windows 8.1 for x64-based Systems (KB3087918)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-18906Security Update for Windows Vista (KB3087918)
PATCH-18907Security Update for Windows 7 (KB3087918)
PATCH-18908Security Update for Windows 8 (KB3087918)
PATCH-18909Security Update for Windows 8.1 (KB3087918)
PATCH-18910Security Update for Windows Vista for x64-based Systems (KB3087918)
PATCH-18911Security Update for Windows 7 for x64-based Systems (KB3087918)
PATCH-18912Security Update for Windows 8 for x64-based Systems (KB3087918)
PATCH-18913Security Update for Windows 8.1 for x64-based Systems (KB3087918)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234