Executive Summary

Summary
TitleVulnerability in Virtual Machine Manager Could Allow Elevation of Privilege (3035898)
Informations
NameMS15-017First vendor Publication2015-02-10
VendorMicrosoftLast vendor Modification2015-02-10
Severity (Vendor) ImportantRevision1.0

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score6.9Attack RangeLocal
Cvss Impact Score10Attack ComplexityMedium
Cvss Expoit Score3.4AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Severity Rating: Important
Revision Note: V1.0 (February 10, 2015): Bulletin published.
Summary: This security update resolves a privately reported vulnerability in Virtual Machine Manager (VMM). The vulnerability could allow elevation of privilege if an attacker logs on an affected system. An attacker must have valid Active Directory logon credentials and be able to log on with those credentials to exploit the vulnerability.

Original Source

Url : https://technet.microsoft.com/en-us/library/security/MS15-017

CWE : Common Weakness Enumeration

%idName
100 %CWE-264Permissions, Privileges, and Access Controls

CPE : Common Platform Enumeration

TypeDescriptionCount
Application1

Information Assurance Vulnerability Management (IAVM)

DateDescription
2015-02-12IAVM : 2015-A-0036 - Microsoft Virtual Machine Manager Privilege Escalation Vulnerability (MS15-017)
Severity : Category II - VMSKEY : V0058749

Nessus® Vulnerability Scanner

DateDescription
2015-02-10Name : The remote host is affected by a privilege escalation vulnerability.
File : smb_nt_ms15-017.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
DateInformations
2015-10-18 17:26:28
  • Multiple Updates
2015-02-12 00:26:28
  • Multiple Updates
2015-02-11 13:24:12
  • Multiple Updates
2015-02-11 09:27:04
  • Multiple Updates
2015-02-10 21:26:50
  • Multiple Updates
2015-02-10 21:16:33
  • First insertion