SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2015-2428

LOW · CVSS 2.1 EPSS 1.78%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-08-15 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 2.1. It affects Microsoft, Windows.

CVE
CVE-2015-2428
Severity
LOW
CVSS
2.1
EPSS
1.78%
Microsoft Windows

Original NVD Description

Object Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels during interaction with object symbolic links that originated in a sandboxed process, which allows local users to gain privileges via a crafted application, aka "Windows Object Manager Elevation of Privilege Vulnerability."