CVE-2015-0096 is an untrusted search path vulnerability affecting multiple versions of Microsoft Windows and Windows Server, allowing local users to gain privileges. This flaw enables remote code execution via a Trojan horse DLL planted in the current working directory, triggered when Windows Explorer accesses a crafted shortcut's icon. With a CVSS score of 9.3 (critical) and a FAUCET Risk Score of 100/100, the vulnerability is easily exploitable over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. Exploit code is publicly available, including Metasploit modules and ExploitDB entries, and it has garnered significant community discussion and media coverage, indicating its high potential for exploitation, though it is not currently listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.