Junglewise Threat Intelligence

CVE-2015-1769: Microsoft Windows Mount Manager Privilege Escalation Vulnerability

CVE-2015-1769 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows 8.1, Microsoft Windows, Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

The Windows Mount Manager improperly processes symbolic links, allowing a physically proximate attacker to execute arbitrary code. This is achieved by connecting a specially crafted USB device to the target system, leading to an elevation of privilege.

Affected products

  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8 Gold
  • Microsoft Windows 8.1 Gold
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows RT Gold, 8.1
  • Microsoft Windows 10

Timeline

  • 2015-08-11: disclosed: Initial vendor advisory and technical blog post published.
  • 2015-08-11: patched: Microsoft released security bulletin MS15-085 to address the issue.
  • 2022-05-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats