#VU5553 Privilege escalation in Windows and Windows Server - CVE-2015-1701
Published: January 31, 2017 / Updated: November 20, 2020
Windows
Windows Server
Microsoft
Description
The weakness exists due to improper access control. A local attacker can create a specially crafted application, execute a callback in userspace and use data from the System token to execute arbitrary code on the system with root privileges.
Successful exploitation of the vulnerability may result in arbitrary code execution on the vulnerable system.
Note: the vulnerability was being actively exploited.