Description
Multiple serious vulnerabilities have been found in Microsoft Windows. Malicious users can exploit these vulnerabilities to bypass security restrictions, gain privileges, execute arbitrary code or obtain sensitive information.
Below is a complete list of vulnerabilities
- Improper information disclosing at Edge can be exploited remotely to obtain sensitive information;
- Improper HTML restrictions at Edge can be exploited remotely to bypass XSS filter;
- Improper memory objects handling at Windows Shell can be exploited remotely via a specially designed toolbar object to execute arbitrary code;
- Improper memory object handling at Microsoft Tablet Input Band can be exploited remotely via a specially designed website to execute arbitrary code;
- Improper memory objects handling at windows kernel can be exploited locally via a specially designed application execute arbitrary code;
- Improper policy enforcement at Windows Trusted Boot can be exploited locally via a specially designed Boot Configuration Data to bypass security restrictions;
- Improper validation at mount points creation can be exploited remotely via a specially designed application to gain privileges.
Technical details
Vulnerability (4) could also be exploited remotely via malicious web site.
(6) could lead to bypass of Trusted Boot integrity validation for BitLocker and Device encryption security features.
Original advisories
- CVE-2015-2548
- CVE-2015-2553
- CVE-2015-6057
- CVE-2015-2515
- CVE-2015-2554
- CVE-2015-2550
- CVE-2015-2552
- CVE-2015-6058
Exploitation
Public exploits exist for this vulnerability.
Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.
Related products
- Microsoft-Windows-Vista-4
- Microsoft-Windows-Server-2012
- Microsoft-Windows-8
- Microsoft-Windows-7
- Microsoft-Windows-Server-2008
- Windows-RT
- Microsoft-Windows-10
CVE list
- CVE-2015-2549 high
- CVE-2015-2548 critical
- CVE-2015-2553 high
- CVE-2015-6057 warning
- CVE-2015-2515 critical
- CVE-2015-2554 high
- CVE-2015-2550 high
- CVE-2015-2552 high
- CVE-2015-6058 warning
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com