<< Back
CVE Number Vulnerability Product Severity Date
MS15-004 Vulnerability in Windows Components Could Allow Elevation of Privilege (3025421) Windows Vista Important 14-01-2015

Technical Information

Brief overview of the risk:
The vulnerability could allow elevation of privilege if an attacker convinces a user to run a specially crafted application.

Detailed Information on the risk:

An elevation of privilege vulnerability exists in the TS WebProxy Windows component. The vulnerability is caused when Windows fails to properly sanitize file paths. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.


Further information on this exploit is available at : MS15-004

Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows 8 for 32-bit Systems
Windows 8 for x64-based Systems
Windows 8.1 for 32-bit Systems
Windows Server 2012 R2
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2012

Affected Software

Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows 8 for 32-bit Systems
Windows 8 for x64-based Systems
Windows 8.1 for 32-bit Systems
Windows Server 2012 R2
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2012