#VU5384 “Use-after-free” error in Windows and Windows Server - CVE-2015-1723

 

#VU5384 “Use-after-free” error in Windows and Windows Server - CVE-2015-1723

Published: January 26, 2017 / Updated: September 14, 2018


Vulnerability identifier: #VU5384
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2015-1723
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: Public exploit is available
Vulnerable software:
Windows
Windows Server
Software vendor:
Microsoft

Description

The vulnerability allows a local attacker to obtain elevated privileges on the target system.

The weakness exists due to use-after-free error. A local attacker can run a specially crafted program to trigger memory corruption and acquire administrative privileges.

Successful exploitation of the vulnerability results in privilege escalation on the vulnerable system.

Remediation

Install update from vendor's website.

External links