关于 CVE-2015-0010 的漏洞信息

1. 漏洞描述
From NVD
The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1, when the CRYPTPROTECTMEMORY_SAME_LOGON option is used, does not check an impersonation token's level, which allows local users to bypass intended decryption restrictions by leveraging a service that (1) has a named-pipe planting vulnerability or (2) uses world-readable shared memory for encrypted data, aka "CNG Security Feature Bypass Vulnerability" or MSRC ID 20707.
From 神龙GPT (AIGC)
在 Microsoft Windows Server 2003 SP2、Windows Vista SP2、Windows Server 2008 SP2 和 R2 SP1、Windows 7 SP1、Windows 8、Windows 8.1、Windows Server 2012 Gold 和 R2、以及 Windows RT Gold 和 8.1 的内核驱动程序中,cng.sys(即 Cryptography 下一代驱动程序)的 CryptProtectMemory 函数,在使用 CRYPTPROTECTMEMORY_SAME_LOGON 选项时,不会检查自仿真令牌的层次,这允许本地用户通过利用一个具有命名管道植入漏洞的服务来绕过预期解密限制,该服务(1)使用可读的共享内存加密数据,即“CNG 安全功能绕过漏洞”或 MSRC ID 20707。
2. 漏洞评分(CVSS)
From NVD
NVD 暂无评分
From 神龙GPT (AIGC)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
3. 漏洞类别
From NVD
NVD 暂无漏洞类别信息
From 神龙GPT (AIGC)
神龙GPT 暂无漏洞类别信息(请耐心等待)
Reference