Information Disclosure Flaw in Windows Media Center by Microsoft
CVE-2015-6127

Currently unrated

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
9 December 2015

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐ŸŸฃ EPSS 72%

What is CVE-2015-6127?

The vulnerability in Windows Media Center allows remote attackers to exploit crafted .mcl files to read arbitrary files on the system. Affected versions include Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1. By leveraging this security issue, attackers can gain access to sensitive data, posing a significant risk to users' privacy. It is crucial for affected users to apply security updates as outlined in Microsoft's advisory to mitigate potential exploitation.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

72% chance of being exploited in the next 30 days.

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.