Microsoft System Center Virtual Machine Manager (VMM) 2012 R2 Update Rollup 4 does not properly validate the roles of users, which allows local users to obtain server and virtual-machine administrative privileges by establishing a server session with Active Directory credentials, aka "Virtual Machine Manager Elevation of Privilege Vulnerability."
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/72473 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1031726 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1034652 | Third Party Advisory VDB Entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-017 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/100428 | VDB Entry |
http://www.securityfocus.com/bid/72473 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1031726 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1034652 | Third Party Advisory VDB Entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-017 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/100428 | VDB Entry |
Configurations
History
21 Nov 2024, 02:22
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/72473 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1031726 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1034652 - Third Party Advisory, VDB Entry | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-017 - Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/100428 - VDB Entry |
Information
Published : 2015-02-11 03:00
Updated : 2024-11-21 02:22
NVD link : CVE-2015-0012
Mitre link : CVE-2015-0012
CVE.ORG link : CVE-2015-0012
JSON object : View
Products Affected
microsoft
- virtual_machine_manager
CWE
CWE-264
Permissions, Privileges, and Access Controls