CVE-2015-0002
The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify that an impersonation token is associated with an administrative account, which allows local users to gain privileges by running AppCompatCache.exe with a crafted DLL file, aka MSRC ID 20544 or "Microsoft Application Compatibility Infrastructure Elevation of Privilege Vulnerability."
CVSS
- Version: 2.0
- Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
- Base score: 7.2
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 14%
- Percentile among all scored CVEs: 96
- Score date: 10/11/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Metasploit module (reliable, widely available exploit) · MS15-001 Microsoft Windows NtApphelpCacheControl Improper Authorization Check
- Published on Exploit-DB · Microsoft Windows 8.1 (x86/x64) - 'ahcache.sys' NtApphelpCacheControl Privilege Escalation (1/1/2015)
Affected technologies (7)
CWEs
- CWE-264
References
- http://secunia.com/advisories/61277
- http://twitter.com/sambowne/statuses/550384131683520512
- http://www.securityfocus.com/bid/71972
- http://www.zdnet.com/article/google-discloses-unpatched-windows-vulnerability/
- https://code.google.com/p/google-security-research/issues/detail?id=118
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99523
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99524
- http://secunia.com/advisories/61277
- http://twitter.com/sambowne/statuses/550384131683520512
- http://www.securityfocus.com/bid/71972
- http://www.zdnet.com/article/google-discloses-unpatched-windows-vulnerability/
- https://code.google.com/p/google-security-research/issues/detail?id=118
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99523
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99524
Raw JSON (NVD)
Show
{
"id": "CVE-2015-0002",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secure@microsoft.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-01-13T22:59:01.253",
"references": [
{
"url": "http://secunia.com/advisories/61277",
"source": "secure@microsoft.com"
},
{
"url": "http://twitter.com/sambowne/statuses/550384131683520512",
"source": "secure@microsoft.com"
},
{
"url": "http://www.securityfocus.com/bid/71972",
"source": "secure@microsoft.com"
},
{
"url": "http://www.zdnet.com/article/google-discloses-unpatched-windows-vulnerability/",
"source": "secure@microsoft.com"
},
{
"url": "https://code.google.com/p/google-security-research/issues/detail?id=118",
"tags": [
"Exploit"
],
"source": "secure@microsoft.com"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-001",
"source": "secure@microsoft.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99523",
"source": "secure@microsoft.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99524",
"source": "secure@microsoft.com"
},
{
"url": "http://secunia.com/advisories/61277",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://twitter.com/sambowne/statuses/550384131683520512",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/71972",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.zdnet.com/article/google-discloses-unpatched-windows-vulnerability/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://code.google.com/p/google-security-research/issues/detail?id=118",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-001",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99523",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99524",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify that an impersonation token is associated with an administrative account, which allows local users to gain privileges by running AppCompatCache.exe with a crafted DLL file, aka MSRC ID 20544 or \"Microsoft Application Compatibility Infrastructure Elevation of Privilege Vulnerability.\""
},
{
"lang": "es",
"value": "La función AhcVerifyAdminContext en ahcache.sys en el componente Application Compatibility en Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold y R2, y Windows RT Gold y 8.1 no verifica que un token de suplantación está asociado con una cuenta administrativa, lo que permite a usuarios locales ganar privilegios mediante la activación de AppCompatCache.exe con un fichero DLL manipulado, también conocido como MSRC ID 20544 o 'vulnerabilidad de la elevación de privilegios de la infraestructura de la compatibilidad de aplicaciones de Microsoft.'"
}
],
"lastModified": "2026-06-17T00:19:24.160",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2B1C231-DE19-4B8F-A4AA-5B3A65276E46"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D229E41-A971-4284-9657-16D78414B93F"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E93068DB-549B-45AB-8E5C-00EB5D8B5CF8"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_rt:-:gold:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC5F631C-5461-4C0B-AE80-079A987912DA"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C6CE5198-C498-4672-AF4C-77AB4BE06C5C"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2ACA9287-B475-4AF7-A4DA-A7143CEF9E57"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:gold:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB506484-7F0C-46BF-8EA6-4FB5AF454CED"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:x64:*:*",
"vulnerable": true,
"matchCriteriaId": "D29A1464-D228-4E0D-8FEA-06B9CBCA7F74"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@microsoft.com"
}