CVE-2015-0006 describes a security feature bypass vulnerability in the Network Location Awareness (NLA) service across various Microsoft Windows versions, including Windows 7, 8, 8.1, Vista, and Server editions. The vulnerability arises because NLA fails to perform mutual authentication when determining a domain connection. This allows remote attackers on a local network to spoof DNS and LDAP responses, tricking the system into an unintended permissive configuration. With a CVSS score of 6.1 (AV:A/AC:L/Au:N/I:C), this vulnerability is considered medium severity. It can be exploited by an unauthenticated attacker on the adjacent network with low attack complexity, leading to a complete compromise of integrity (C:N/I:C/A:N). While the direct impact is integrity compromise, this could facilitate further attacks. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:L/Au:N/C:N/I:C/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.