Home / bulletins

MS15-006 - Important: Vulnerability in Windows Error Reporting Could Allow Security Feature Bypass (3004365) - Version: 1.1

Posted on 22 January 2015

There is an newer version: MS15-006 - Version: 2.0

Important

Severity Rating: Important
Revision Note: V1.1 (January 21, 2015): Bulletin revised to correct Server Core installation entries in the Affected Software and Severity Ratings tables. This is an informational change only. Customers who have already successfully installed the update do not have to take any action.
Summary: This security update resolves a privately reported vulnerability in Windows Error Reporting (WER). The vulnerability could allow security feature bypass if successfully exploited by an attacker. An attacker who successfully exploited this vulnerability could gain access to the memory of a running process. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Link

Other versions

 

TOP