(MS15-028) Vulnerability in Windows Task Scheduler Could Allow Security Feature Bypass (3030377)
Publish Date: 02 avril 2015
Gravité: : Élevé
Identifiant(s) CVE: : CVE-2015-0084
Date du conseil: 02 avril 2015
Description
This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow a user with limited privileges on an affected system to leverage Task Scheduler to execute files that they do not have permissions to run. An attacker who successfully exploited this vulnerability could bypass access control list (ACL) checks and run privileged executables.
Solutions
Affected software and version:
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
- Windows 8 for 32-bit Systems
- Windows 8 for x64-based Systems
- Windows 8.1 for 32-bit Systems
- Windows 8.1 for x64-based Systems
- Windows Server 2012
- Windows Server 2012 R2
- Windows RT
- Windows RT 8.1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2 (Server Core installation)