Vulnerability record · CVE-2015-0016 · published 13 January 2015
CVE-2015-0016: Microsoft Windows TS WebProxy directory traversal privilege escalation
Microsoft · Windows 7
The TS WebProxy (TSWbPrxy) component in multiple Windows versions mishandles crafted pathnames, allowing a directory traversal that lets an attacker move from Low Integrity to Medium Integrity. Because it breaks the Internet Explorer sandbox boundary, it matters as a privilege-escalation primitive rather than a standalone remote compromise.
Description
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Directory Traversal Elevation of Privilege Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with public exploits and a very high EPSS score, but exploitation requires local access plus user interaction and only yields Medium Integrity.
What it is
The TS WebProxy (TSWbPrxy) component in multiple Windows versions mishandles crafted pathnames, allowing a directory traversal that lets an attacker move from Low Integrity to Medium Integrity. Because it breaks the Internet Explorer sandbox boundary, it matters as a privilege-escalation primitive rather than a standalone remote compromise.
Impact
An attacker who already runs code at Low Integrity can escape the sandbox and gain Medium Integrity privileges, enabling further access to user data and system resources.
Attack surface
Reached locally through the TS WebProxy component, but the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), consistent with a crafted executable pathname triggered in a browsing or file-opening context.
Exploitation
CVE-2015-0016 is listed in CISA KEV (added 2022-05-25) and has an EPSS 30-day probability of 0.7594 (99.5th percentile); multiple references are tagged Exploit, including public exploit-db and Packet Storm entries.
What to do
- Apply the Microsoft MS15-004 update for all affected Windows versions (Vista SP2, 7 SP1, 8, 8.1, RT, RT 8.1, Server 2008 R2 SP1, Server 2012 Gold/R2).
- Retire or isolate unsupported end-of-life platforms that cannot receive the patch.
- Enforce least privilege and application control so untrusted code cannot execute at Low Integrity and attempt the traversal.
- Reduce exposure to untrusted executables and web content that could trigger the crafted pathname.
- Verify KEV remediation is complete by the CISA due date of 2022-06-15.
Detection
- Monitor for processes spawning from Low Integrity contexts that subsequently run at Medium Integrity, especially involving TSWbPrxy.
- Alert on executable pathnames containing traversal sequences (../) reaching TS WebProxy or RDP-related components.
- Hunt for known public exploit artifacts tied to MS15-004 and CVE-2015-0016 in endpoint telemetry.
- Audit hosts still running unpatched affected Windows builds against the MS15-004 baseline.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-0016 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Windows TS WebProxy Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-0016 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-0016), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.