CVE-2015-0016
HIGH KEVWindows TS WebProxy - Directory Traversal Elevation of Privilege via Crafted Executable Pathname
Title source: llmExploitation Summary
CVE-2015-0016 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 25, 2022.
EIP tracks 2 public exploits from researchers including Metasploit, Unknown, Henry Li, juan vazquez, including a Metasploit module exploits/windows/local/ms15_004_tswbproxy.
AI-analyzed exploit summary This Metasploit module exploits CVE-2015-0016, a sandbox escape vulnerability in Microsoft Remote Desktop Services Web Proxy for Internet Explorer, allowing execution of code with Medium Integrity on Windows 7 SP1 and prior (32-bit). It leverages a process creation policy flaw to bypass Protected Mode.
Description
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Directory Traversal Elevation of Privilege Vulnerability."
Exploits (2)
This Metasploit module exploits CVE-2015-0016, a sandbox escape vulnerability in Microsoft Remote Desktop Services Web Proxy for Internet Explorer, allowing execution of code with Medium Integrity on Windows 7 SP1 and prior (32-bit). It leverages a process creation policy flaw to bypass Protected Mode.
This Metasploit module exploits CVE-2015-0016, a sandbox escape vulnerability in Microsoft Remote Desktop Services Web Proxy (TSWbPrxy.exe). It bypasses Internet Explorer's Protected Mode by abusing a process creation policy, allowing code execution at Medium Integrity on Windows 7 SP1 and prior 32-bit systems.
References (10)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H