<< Back
CVE Number Vulnerability Product Severity Date
MS15-098 Vulnerabilities in Windows Journal Could Allow Remote Code Execution (3089669) Windows Vista Critical 09-09-2015

Technical Information

Brief overview of the risk:
Remote code execution vulnerabilities exist in Microsoft Windows when a specially crafted Journal file is opened in Windows Journal.

Detailed Information on the risk:

Remote code execution vulnerabilities exist in Microsoft Windows when a specially crafted Journal file is opened in Windows Journal. An attacker who successfully exploited the vulnerabilities could cause arbitrary code to execute in the context of the current user. If a user is logged on with administrative user rights, an attacker could take control of the affected system.

Further information on this exploit is available at : MS15-098

Windows Vista Service Pack 2 
Windows Vista x64 Edition Service Pack 2 
Windows Server 2008 for 32-bit Systems Service Pack 2 
Windows Server 2008 for x64-based Systems Service Pack 2 
Windows 7 for 32-bit Systems Service Pack 1 
Windows 7 for x64-based Systems Service Pack 1 
Windows Server 2008 R2 for x64-based Systems Service Pack 1 
Windows 8 for 32-bit Systems 
Windows 8 for x64-based Systems 
Windows 8.1 for 32-bit Systems 
Windows 8.1 for x64-based Systems 
Windows Server 2012 R2 
Windows 10 for 32-bit Systems
Windows 10 for x64-based Systems

Affected Software

Windows Vista Service Pack 2 
Windows Vista x64 Edition Service Pack 2 
Windows Server 2008 for 32-bit Systems Service Pack 2 
Windows Server 2008 for x64-based Systems Service Pack 2 
Windows 7 for 32-bit Systems Service Pack 1 
Windows 7 for x64-based Systems Service Pack 1 
Windows Server 2008 R2 for x64-based Systems Service Pack 1 
Windows 8 for 32-bit Systems 
Windows 8 for x64-based Systems 
Windows 8.1 for 32-bit Systems 
Windows 8.1 for x64-based Systems 
Windows Server 2012 R2 
Windows 10 for 32-bit Systems
Windows 10 for x64-based Systems