CVE-2015-6111

Description

IPSec in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles encryption negotiation, which allows remote authenticated users to cause a denial of service (system hang) via crafted IP traffic, aka Windows IPSec Denial of Service Vulnerability.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.105

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows 8 (KB3102939)Windows
Security Update for Windows 8.1 (KB3102939)Windows
Security Update for Windows 8 for x64-based Systems (KB3102939)Windows
Security Update for Windows Server 2012 (KB3102939)Windows
Security Update for Windows 8.1 for x64-based Systems (KB3102939)Windows
Security Update for Windows Server 2012 R2 (KB3102939)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-19376Security Update for Windows 8 (KB3102939)
PATCH-19377Security Update for Windows 8.1 (KB3102939)
PATCH-19378Security Update for Windows 8 for x64-based Systems (KB3102939)
PATCH-19379Security Update for Windows Server 2012 (KB3102939)
PATCH-19380Security Update for Windows 8.1 for x64-based Systems (KB3102939)
PATCH-19381Security Update for Windows Server 2012 R2 (KB3102939)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234