CERT-In Vulnerability Note
CIVN-2015-0307
Multiple Vulnerabilities in Microsoft Windows Kernel
Original Issue Date:December 09, 2015
Severity Rating: HIGH
Systems Affected
- Windows Vista and Vista x64 Edition Service Pack 2
- Windows Server 2008 for 32-bit, x64 based and Itanium based Systems Service Pack 2
- Windows 7 for 32-bit and x64 based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based and Itanium based Systems Service Pack 1
- Windows 8 and 8.1 for 32-bit and x64 based Systems
- Windows Server 2012 and 2012 R2
- Windows RT and RT 8.1
- Windows 10 and Windows 10 version 1511 for 32-bit and x64 based Systems
- Server Core installation option for Windows Server 2008 Service Pack 2 (for 32 bit and 64 based systems)
- Server Core installation option for Windows Server 2008 R2 Service Pack 1 (for 64 based systems)
- Server Core installation option for Windows Server 2012 and 2012 R2
Overview
Multiple vulnerabilities have been reported in Microsoft Windows which could be exploited by an attacker to execute arbitrary code on the targeted system and gain elevated privileges.
Description
Multiple vulnerabilities exist in Microsoft Windows kernel due to improper handling of the memory objects. A local attacker with access to the targeted system could exploit these vulnerabilities by logging in the targeted system and running specially crafted software.
Successful exploitation of these vulnerabilities could allow an attacker to take complete control of the targeted system, execute arbitrary code, view, change, or delete data and create new accounts with admin privileges.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS15-135
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/ms15-135
References
Microsoft
https://technet.microsoft.com/en-us/library/security/ms15-135
Symantec
http://www.symantec.com/security_response/vulnerability.jsp?bid=78514&om_rssid=sr-advisories
http://www.symantec.com/security_response/vulnerability.jsp?bid=78513&om_rssid=sr-advisories
CVE Name
CVE-2015-6171
CVE-2015-6173
CVE-2015-6174
CVE-2015-6175
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|