CVE-2015-0012
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Microsoft System Center Virtual Machine Manager (VMM) 2012 R2 Update Rollup 4 does not properly validate the roles of users, which allows local users to obtain server and virtual-machine administrative privileges by establishing a server session with Active Directory credentials, aka "Virtual Machine Manager Elevation of Privilege Vulnerability."
Microsoft System Center Virtual Machine Manager (VMM) 2012 R2 Update Rollup 4 no valida correctamente los roles de los usuarios, lo que permite a usuarios locales obtener privilegios administrativos de servidor y de máquina virtual mediante la establecimiento de una sesión de servidor con las credenciales Active Directory, también conocido como 'vulnerabilidad de la elevación de privilegios de gestor de la máquina virtual.'
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-11-18 CVE Reserved
- 2015-02-11 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/72473 | Third Party Advisory | |
http://www.securitytracker.com/id/1031726 | Third Party Advisory | |
http://www.securitytracker.com/id/1034652 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/100428 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-017 | 2018-11-20 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Virtual Machine Manager Search vendor "Microsoft" for product "Virtual Machine Manager" | 2012 Search vendor "Microsoft" for product "Virtual Machine Manager" and version "2012" | r2_rollup4 |
Affected
|