CVE-2015-6175
Microsoft Windows Kernel Privilege Escalation Vulnerability
Description
CVE-2015-6175 is a privilege escalation vulnerability in the Microsoft Windows kernel that allows local users to gain elevated privileges through a specially crafted application. The vulnerability exists in the way the Windows kernel handles objects in memory, and can be exploited by an attacker with local access to the system to escalate from a standard user to higher privilege levels. This Windows kernel vulnerability is particularly valuable in post-exploitation scenarios where attackers need elevated access. CISA has listed CVE-2015-6175 in the Known Exploited Vulnerabilities catalog, confirming active exploitation, and its EPSS percentile of 86.0% indicates a high probability of exploitation activity.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows 10 1507 | - |
Multiple CVSS Assessments
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References
- http://www.securitytracker.com/id/1034334(Broken Link, Third Party Advisory, VDB Entry)
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-135(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-6175(US Government Resource)
Weakness Type
No specific CWE has been assigned to CVE-2015-6175 in the NVD database. The vulnerability resides in the Windows kernel and involves improper handling of objects in memory. When a specially crafted application triggers specific kernel code paths, the kernel mismanages memory objects, leading to a condition that can be exploited for privilege escalation. This class of kernel vulnerability typically involves improper object lifecycle management that allows an attacker to manipulate kernel memory state.
Learn more: CWE Overview
Impact Analysis
CVE-2015-6175 enables local privilege escalation through the Windows kernel. The vulnerability requires a local attacker to run a specially crafted application, but once exploited, it provides elevated privileges on the system. Confidentiality (High): Kernel-level privilege escalation grants the attacker access to all data on the system, including protected kernel memory, credentials of all users, and encrypted data accessible through system-level keys. Integrity (High): With kernel-level access, the attacker can modify any file, install rootkits, manipulate kernel data structures, and alter the operating system at its most fundamental level. Availability (High): Kernel compromise enables the attacker to crash the system, disable security mechanisms, or permanently alter system behavior. With an EPSS percentile of 86.0%, this vulnerability has a high probability of active exploitation, commonly leveraged in post-exploitation attack chains.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2015-6175 by listing it in the Known Exploited Vulnerabilities catalog, with a remediation deadline of June 15, 2022. The EPSS percentile of 86.0% indicates a high likelihood of exploitation activity. Windows kernel privilege escalation vulnerabilities are consistently among the most valuable tools in an attacker's post-exploitation toolkit, used to elevate from initial user-level access to SYSTEM or kernel-level privileges needed for installing persistent rootkits, disabling security software, or accessing protected resources.
Remediation
- Apply Microsoft security updates per vendor instructions as required by the CISA KEV catalog. Install all relevant patches that address CVE-2015-6175 in the Windows kernel.
- Ensure all Windows systems run supported, current versions with the latest security updates applied. Kernel vulnerabilities are regularly patched in Microsoft's monthly security updates.
- Implement least privilege principles across the organization. Users should operate with standard user accounts rather than administrator accounts for daily tasks, and application whitelisting should prevent execution of unauthorized applications.
- Deploy endpoint detection and response (EDR) solutions capable of detecting kernel exploitation attempts, unusual privilege escalation events, and suspicious application behavior that may indicate exploitation of kernel vulnerabilities.
- Enable virtualization-based security (VBS) and Credential Guard on supported Windows versions to provide hardware-enforced isolation of sensitive kernel operations and credential storage, limiting the impact of kernel-level compromise.
Technical Details
CVE-2015-6175 is a privilege escalation vulnerability in the Microsoft Windows kernel. The flaw exists in how the kernel handles objects in memory when processing requests from user-mode applications. A locally authenticated attacker can craft an application that invokes specific system calls or kernel interfaces in a way that triggers improper object handling, leading to memory corruption in kernel space. By carefully controlling the corruption, the attacker can overwrite kernel data structures to elevate their process token privileges from a standard user to SYSTEM level. The local attack vector means the attacker must already have the ability to execute code on the target system, making this vulnerability most relevant in scenarios where initial access has been gained through another vulnerability, compromised credentials, or legitimate but limited access.
Frequently Asked Questions
Is CVE-2015-6175 being actively exploited?
Yes, CVE-2015-6175 is actively exploited. CISA confirmed its inclusion in the Known Exploited Vulnerabilities catalog with a remediation deadline of June 15, 2022. The EPSS percentile of 86.0% indicates a high probability of exploitation activity.
What products are affected by CVE-2015-6175?
CVE-2015-6175 affects the Microsoft Windows kernel. Multiple Windows versions are affected. Organizations should consult Microsoft security bulletins for specific version details and available patches.
How do I fix CVE-2015-6175?
Apply Microsoft security updates that address this kernel vulnerability. Implement least privilege access controls, deploy EDR solutions for kernel exploitation detection, and enable virtualization-based security where supported.
How severe is CVE-2015-6175?
CVE-2015-6175 is a kernel-level privilege escalation vulnerability with an EPSS percentile of 86.0%. While it requires local access, successful exploitation grants SYSTEM-level privileges, enabling complete control over the affected system and the ability to bypass virtually all software-based security controls.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.