Junglewise Threat Intelligence

CVE-2015-0016: Microsoft Windows TS WebProxy Directory Traversal Vulnerability

CVE-2015-0016 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Windows Vista, Microsoft Windows 8.1, Microsoft Windows, Microsoft Windows Server 2012, Microsoft Windows 7, Microsoft Windows Server 2008 R2. Vendors: Microsoft.

Executive brief

A directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component of Microsoft Windows allows remote attackers to escalate privileges. By using a crafted pathname in an executable file, an attacker can transition from Low Integrity to Medium Integrity, effectively escaping the Internet Explorer sandbox.

Affected products

  • Microsoft Windows Vista SP2
  • Microsoft Windows 7 SP1
  • Microsoft Windows Server 2008 R2 SP1
  • Microsoft Windows 8 Gold
  • Microsoft Windows 8.1 -
  • Microsoft Windows Server 2012 Gold and R2
  • Microsoft Windows RT Gold and 8.1

Timeline

  • 2015-01-13: disclosed: Initial Microsoft security bulletin MS15-004 published
  • 2015-01-13: patched: Microsoft released updates to address the vulnerability
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-25: exploited: Confirmed as exploited in the wild per CISA KEV entry

Related threats