EXPOSURES › CVE-2015-0016
CVE-2015-0016
HIGH ⌖ ON CISA KEV · EXPLOITEDA directory traversal flaw in Windows TS WebProxy allowed remote attackers to escalate privileges.
The TS WebProxy component in Windows contained a directory traversal vulnerability that enabled remote attackers to escalate privileges. DIB organizations must ensure all Windows systems are patched against known directory traversal flaws, as unpatched vulnerabilities in core OS components can lead to privilege escalation and system compromise. This failure highlights the risk of relying on unpatched legacy components in production environments.
Shame score — A directory traversal vulnerability in a core Windows component was actively exploited in the wild (KEV), indicating negligence in patching and allowing remote attackers to escalate privileges.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |