CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
MS15-006 | Vulnerability in Windows Error Reporting Could Allow Security Feature Bypass (3004365) | Windows 8 | Important | 14-01-2015 |
Technical Information
Brief overview of the risk:
This security update resolves a privately reported vulnerability in Windows Error Reporting (WER). The vulnerability could allow security feature bypass if successfully exploited by an attacker. An attacker who successfully exploited this vulnerability could gain access to the memory of a running process.
Detailed Information on the risk:
A security feature bypass vulnerability exists in Windows Error Reporting (WER) that allows administrative users to view the memory contents of processes protected by “Protected Process Light.” “Protected Process Light” inhibits debugging of critical system processes by arbitrary users on the system, even administrative users. An attacker who successfully exploited this vulnerability could access the memory of a running process protected by “Protected Process Light.”
Further information on this exploit is available at : MS15-006
Windows 8 for x64-based Systems
Windows 8.1 for 32-bit Systems
Windows 8.1 for x64-based Systems
Windows Server 2012
Windows Server 2012 R2
Affected Software
Windows 8 for 32-bit SystemsWindows 8 for x64-based Systems
Windows 8.1 for 32-bit Systems
Windows 8.1 for x64-based Systems
Windows Server 2012
Windows Server 2012 R2