CVE-2015-2373 is a critical Remote Code Execution (RCE) vulnerability affecting the RDP server service in Microsoft Windows 7 SP1, Windows 8, and Windows Server 2012. An unauthenticated remote attacker can exploit this by sending a series of crafted packets, allowing for complete compromise of the affected system. With a CVSS score of 10.0 and an EPSS score indicating high exploitability, this vulnerability poses a severe risk. While there is no public exploit code available in common frameworks like Metasploit or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.