CVE-2015-2474 is a critical memory corruption vulnerability affecting Microsoft Windows Vista SP2 and Server 2008 SP2, allowing remote authenticated users to execute arbitrary code through crafted strings in SMB server error-logging actions. With a CVSS score of 9.0, it presents a high severity risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is available, and it is not listed in CISA's KEV catalog, the vulnerability has garnered some community discussion, indicating awareness among security professionals.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Microsoft Windows SMB v1 Service Principal Name Handling Remote Buffer Overflow
Aug 25, 2015[R1] Microsoft Windows SMB v1 Service Principal Name Handling Remote Buffer Overflow
Aug 24, 2015[R1] Microsoft Windows SMB v1 Service Principal Name Handling Remote Buffer Overflow
Aug 24, 2015