VDB

CVE-2015-0008

CVE-2015-0008 PUBLISHED CVSS 8.300000190734863 HIGH

The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authentication from the server to the client, which allows remote attackers to execute arbitrary code by making crafted data available on a UNC share, as demonstrated by Group Policy data from a spoofed domain controller, aka "Group Policy Remote Code Execution Vulnerability."

EPSS 10.20% · 93.3th percentile

Risk Scores

CVSS 2.0
8.300000190734863
EPSS Score
10.20%
93.3th percentile

Affected Products

VendorProductVersions
microsoftwindows_7
microsoftwindows_server_2008r2, r2
microsoftwindows_server_2003
MicrosoftWindows
microsoftwindows_rt_8.1
microsoftwindows_server_2012r2
microsoftwindows_rt
n/an/an/a
microsoftwindows_8.1
microsoftwindows_8
microsoftwindows_vista

Timeline

  • Feb 11, 2015 CVE Published
  • Oct 29, 2019 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Mar 12, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • Jul 16, 2023 EPSS Score
  • Jul 26, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›