Untrusted Search Path Vulnerability in Microsoft Windows Media Device Manager
CVE-2015-2369

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
14 July 2015

Summary

The untrusted search path vulnerability in Windows Media Device Manager affects several Windows operating systems and allows local users to exploit a weakness by embedding a Trojan horse DLL in the current working directory. This may lead to unauthorized privilege escalation, as the system might execute the malicious DLL rather than the legitimate one. The risk is particularly pressing when unverified files are accessible in directories containing .rtf files, facilitating potential remote code execution.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.