VulnerabilityModified
CVE-2015-2529
The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability."
LOW 2.1EPSS 2.29%
Does this matter?
Lower severity and a low EPSS score (2.29%). Track it; it rarely justifies an emergency change on its own.
Description
The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability."
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- microsoft/windows 10 · microsoft/windows 8.1 · microsoft/windows rt 8.1 · microsoft/windows server 2012
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/76602Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1033485Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-097Patch, Vendor Advisory
- http://www.securityfocus.com/bid/76602Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1033485Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-097Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.