7.2
CVSSv2

CVE-2015-2524

Published: 09/09/2015 Updated: 14/05/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2528.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 8 -

microsoft windows server 2012 -

microsoft windows 8.1 -

microsoft windows 10 -

microsoft windows rt -

microsoft windows rt 8.1 -

microsoft windows server 2012 r2

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=437 Windows: CreateObjectTask SettingsSyncDiagnostics Elevation of Privilege Platform: Windows 81 Update (I don’t believe it’s available in earlier Windows versions) Class: Elevation of Privilege Summary: The CreateObjectTask scheduled task initializes a user accessi ...