CVE-2015-2553
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles junctions during mountpoint creation, which makes it easier for local users to gain privileges by leveraging certain sandbox access, aka "Windows Mount Point Elevation of Privilege Vulnerability."
- Affected products
- Windows, Windows 10, Windows 7, Windows 8, Windows 8.1, Windows Rt, Windows Server 2008, Windows Server 2012
- Microsoft Windows 10
- All versions
- Microsoft Windows 7
- All versions
- Microsoft Windows 8
- All versions
- Microsoft Windows 8.1
- All versions
- Microsoft Windows Rt
- All versions
- Microsoft Windows Rt 8.1
- All versions
- Fix
- Available
- CVSS 2.0
- 7.2 HIGH
- EPSS
- 3.3% (88th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2015-10-14
CVE-2015-2553 at NVD
8 known exploits for CVE-2015-2553
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (2)
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (2)
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (2) (MS16-008)
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (1) (MS16-008)
Windows 10 Sandboxed Mount Reparse Point Creation Mitigation Bypass (MS15-111)
Microsoft Windows 10 - Sandboxed Mount Reparse Point Creation Mitigation Bypass (MS15-111)