7.2
CVSSv2

CVE-2015-2528

Published: 09/09/2015 Updated: 08/09/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2524.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 10 -

microsoft windows rt -

microsoft windows server 2012 -

microsoft windows 8.1 -

microsoft windows server 2008 r2

microsoft windows 7 -

microsoft windows server 2008 -

microsoft windows rt 8.1 -

microsoft windows server 2012 r2

microsoft windows 8 -

microsoft windows vista -

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=439 Windows: CreateObjectTask TileUserBroker Elevation of Privilege Platform: Windows 81 Update (I don’t believe it’s available in earlier Windows versions) Class: Elevation of Privilege Summary: The CreateObjectTask scheduled task initializes a user accessible syste ...