ZeroHour

CVE-2015-1769

KEVmass

Local Privilege Escalation via Symlink Flaw in Microsoft Windows Mount Manager

CISA: Microsoft Windows Mount Manager Privilege Escalation Vulnerability

CVSS
EPSS
4%p90
Published
KEV added
AI analysis

CVE-2015-1769 is an elevation-of-privilege flaw (CWE-264) in the Windows Mount Manager, the component that handles disk and mount-point management, caused by improper processing of symbolic links. A local attacker who can already run code on a target Windows machine can supply a crafted symbolic link or mount point that Mount Manager mishandles, causing operations to execute with elevated rights. Successful exploitation yields higher privileges, up to SYSTEM/administrator, which attackers typically use to harden a foothold, disable defenses, or move laterally, usually in combination with a separate initial-access or code-execution flaw. Per CISA, Microsoft Windows is affected; the flaw was addressed in Microsoft's August 2015 Mount Manager update (MS15-085), so the currently vulnerable population is largely unpatched or legacy systems. The issue is in CISA KEV (added 2022-05-25), indicating known in-the-wild exploitation, with a 4.1% EPSS probability of exploitation in the next 30 days (90th percentile); no public PoC is known and ransomware usage is undetermined.

What to do: Apply updates per vendor instructions: install the Mount Manager fix from Microsoft bulletin MS15-085 (August 2015) on any Windows system lacking it, prioritizing hosts referenced in CISA KEV. Audit legacy Windows builds that may have missed this 2015 update, and as interim hardening restrict interactive logon by untrusted users on those machines. Since this is a local privilege escalation, hunt on unpatched systems for signs it was chained after an initial foothold, including in intrusion-to-ransomware sequences.

Affected
Microsoft Windows
Estimated exposure
masshundreds of millions of Windows devices by ubiquity, though the currently vulnerable count is limited to unpatched/legacy systems (patch available since Aug… — Windows runs on the large majority of enterprise and consumer endpoints worldwide, but because a vendor patch has been available since August 2015, the realistic vulnerable population is the unknown subset of legacy or unmaintained…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Windows
Weakness
CWE-264

In the news