#VU5568 Memory corruption in Windows and Windows Server - CVE-2015-2507 

 

#VU5568 Memory corruption in Windows and Windows Server - CVE-2015-2507

Published: February 1, 2017 / Updated: September 14, 2018


Vulnerability identifier: #VU5568
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2015-2507
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: Public exploit is available
Vulnerable software:
Windows
Windows Server
Software vendor:
Microsoft

Description

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to boundary error in Adobe Type Manager Library. A local attacker can execute a specially crafted program, trigger memory corruption and gain SYSTEM privileges.

Successful exploitation of the vulnerability may result in full control of the vulnerable system.


Remediation

Install update from vendor's website.

External links