CVE-2015-0016
KEVmassDirectory Traversal Privilege Escalation in Microsoft Windows TS WebProxy
CISA: Microsoft Windows TS WebProxy Directory Traversal Vulnerability
CVE-2015-0016 is a directory traversal flaw (CWE-22) in the TS WebProxy (TSWbPrxy) component that ships with Microsoft Windows. A remote attacker can submit crafted path input that the component processes without properly restricting path traversal, allowing content to be placed or retrieved outside the intended directory. Successful exploitation lets the attacker escalate privileges on the targeted Windows system. Any Windows installation containing the vulnerable TS WebProxy component is affected; the available data does not enumerate specific Windows version ranges, and Microsoft shipped the fix with its January 2015 security updates, so unpatched systems remain at risk. The flaw was added to the CISA KEV catalog on 2022-05-25, confirming known in-the-wild exploitation; EPSS is high at 75.9% (99th percentile), no public proof-of-concept is known, and any ransomware association is unknown.
What to do: Apply Microsoft's January 2015 security updates (or later servicing/cumulative updates) to all Windows systems, prioritizing servers that run Remote Desktop Gateway/RD Web Access or RemoteApp and Desktop Connections where TS WebProxy is actively exercised, in line with CISA's required action to apply updates per vendor instructions. Verify the TSWbPrxy component is updated across the estate and hunt for exploitation activity on unpatched hosts; ransomware association is unknown, so treat any confirmed compromise accordingly.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Windows
- Weakness
- CWE-22