CVE-2015-2525
high · 7.2Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass intended filesystem restrictions and delete arbitrary files via unspecified vectors, aka "Windows Task File Deletion Elevation of Privilege Vulnerability."
7.2
CVSS
31.5%
EPSS (exploit prob.)
98th
EPSS percentile
2015-09-09
Published
AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-264
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows_10 | all versions |
| microsoft | windows_7 | all versions |
| microsoft | windows_8 | all versions |
| microsoft | windows_8.1 | all versions |
| microsoft | windows_rt | all versions |
| microsoft | windows_rt_8.1 | all versions |
| microsoft | windows_server_2008 | all versions |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2012 | all versions |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_vista | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/76653
- http://www.securitytracker.com/id/1033494
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-102
- https://www.exploit-db.com/exploits/38200/
- http://www.securityfocus.com/bid/76653
- http://www.securitytracker.com/id/1033494
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-102
- https://www.exploit-db.com/exploits/38200/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-2525