Vulnerabilities > CVE-2015-1674 - 7PK - Security Features vulnerability in Microsoft products
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate an unspecified address, which allows local users to bypass the KASLR protection mechanism, and consequently discover the cng.sys base address, via a crafted application, aka "Windows Kernel Security Feature Bypass Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 6 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Windows - CNG.SYS Kernel Security Feature Bypass PoC (MS15-052). CVE-2015-1674. Local exploit for windows platform |
file | exploits/windows/local/37052.c |
id | EDB-ID:37052 |
last seen | 2016-02-04 |
modified | 2015-05-18 |
platform | windows |
port | |
published | 2015-05-18 |
reporter | 4B5F5F4B |
source | https://www.exploit-db.com/download/37052/ |
title | Windows - CNG.SYS Kernel Security Feature Bypass PoC MS15-052 |
type | local |
Msbulletin
bulletin_id | MS15-052 |
bulletin_url | |
date | 2015-05-12T00:00:00 |
impact | Security Feature Bypass |
knowledgebase_id | 3050514 |
knowledgebase_url | |
severity | Important |
title | Vulnerability in Windows Kernel Could Allow Security Feature Bypass |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS15-052.NASL |
description | The remote Windows host is affected by a security feature bypass vulnerability due to a failure to properly validate memory addresses by the Windows kernel. A remote attacker can exploit this flaw, via a specially crafted application, to bypass the Kernel Address Space Layout Randomization (KASLR), resulting in the disclosure of the base address of the Cryptography Next Generation (CNG) kernel-mode driver (cng.sys). |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 83361 |
published | 2015-05-12 |
reporter | This script is Copyright (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/83361 |
title | MS15-052: Vulnerability in Windows Kernel Could Allow Security Feature Bypass (3050514) |
code |
|