![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.805448 |
Category: | Windows : Microsoft Bulletins |
Title: | Microsoft Group Policy Remote Code Execution Vulnerability (3000483) |
Summary: | This host is missing a critical security; update according to Microsoft Bulletin MS15-011. |
Description: | Summary: This host is missing a critical security update according to Microsoft Bulletin MS15-011. Vulnerability Insight: The flaw is due to remote code execution vulnerability in the way Group Policy receives and applies policy data if a domain-joined system is connected to a domain controller Vulnerability Impact: Successful exploitation will allow context-dependent to execute arbitrary code. Failed exploit attempts will result in a denial-of-service condition. Affected Software/OS: - Microsoft Windows 2003 x32/x64 Service Pack 2 - Microsoft Windows Vista x32/x64 Service Pack 2 and prior - Microsoft Windows Server 2008 x32 Service Pack 2 - Microsoft Windows Server 2008 R2 x64 Service Pack 1 - Microsoft Windows Server 2008 x64 Service Pack 2 - Microsoft Windows 7 x32/x64 Service Pack 1 - Microsoft Windows 8 x32/x64 - Microsoft Windows 8.1 x32/x64 - Microsoft Windows Server 2012/2012R2 Solution: The vendor has released updates. Please see the references for more information. CVSS Score: 8.3 CVSS Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2015-0008 BugTraq ID: 72477 http://www.securityfocus.com/bid/72477 CERT/CC vulnerability note: VU#787252 http://www.kb.cert.org/vuls/id/787252 http://packetstormsecurity.com/files/155002/Microsoft-Windows-Server-2012-Group-Policy-Remote-Code-Execution.html https://www.jasadvisors.com/additonal-jasbug-security-exploit-info/ Microsoft Security Bulletin: MS15-011 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-011 http://www.securitytracker.com/id/1031719 XForce ISS Database: ms-grouppolicy-cve20150008-code-exec(100426) https://exchange.xforce.ibmcloud.com/vulnerabilities/100426 |
Copyright | Copyright (C) 2015 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |