VDB
CVE-2015-0008
CVE-2015-0008
PUBLISHED
CVSS 8.300000190734863 HIGH
The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authentication from the server to the client, which allows remote attackers to execute arbitrary code by making crafted data available on a UNC share, as demonstrated by Group Policy data from a spoofed domain controller, aka "Group Policy Remote Code Execution Vulnerability."
EPSS 10.20% · 93.3th percentile
Risk Scores
CVSS 2.0
8.300000190734863
EPSS Score
10.20%
93.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_7 | |
| microsoft | windows_server_2008 | r2, r2 |
| microsoft | windows_server_2003 | |
| Microsoft | Windows | |
| microsoft | windows_rt_8.1 | |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_rt | |
| n/a | n/a | n/a |
| microsoft | windows_8.1 | |
| microsoft | windows_8 | |
| microsoft | windows_vista |
Timeline
- Feb 11, 2015 CVE Published
- Oct 29, 2019 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 12, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
- Jul 26, 2023 EPSS Score
References
- MS15-011 vendor-advisory
- VU#787252 third-party-advisory
- ms-grouppolicy-cve20150008-code-exec(100426) vdb
- http://blogs.technet.com/b/srd/archive/2015/02/10/ms15-011-amp-ms15-014-hardening-group-policy.aspx url
- 1031719 vdb
- 72477 vdb
- https://www.jasadvisors.com/additonal-jasbug-security-exploit-info/ url
- http://packetstormsecurity.com/files/155002/Microsoft-Windows-Server-2012-Group-Policy-Remote-Code-Execution.html url
- https://technet.microsoft.com/fr-fr/library/security/MS15-011 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-0008 advisory
- https://www.jasadvisors.com/additonal-jasbug-security-exploit-info url