Vulnerability record · CVE-2015-1769 · published 15 August 2015
CVE-2015-1769: Windows Mount Manager symlink mishandling allows local privilege escalation
Microsoft · Windows 10
The Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core OS component present across many Windows versions, a successful attack can elevate privileges on the affected host.
Description
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Mount Manager Elevation of Privilege Vulnerability."
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in the CISA KEV catalog with confirmed in-the-wild exploitation and affects a broad set of Windows versions, though it requires physical access.
What it is
The Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core OS component present across many Windows versions, a successful attack can elevate privileges on the affected host.
Impact
An attacker who can connect a malicious USB device gains the ability to execute arbitrary code with elevated privileges on the target system.
Attack surface
Reached only through physical access: the attacker must connect a crafted USB device to the machine. The CVSS vector (AV:P/PR:L/UI:N) confirms physical proximity and low privileges are required, with no user interaction.
Exploitation
CVE-2015-1769 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-25), indicating exploitation in the wild; EPSS 30-day probability is 0.04111 (90th percentile). No ransomware campaign use is documented.
What to do
- Apply the Microsoft MS15-085 update to all affected Windows versions (Vista SP2 through Windows 10, Server 2008 through 2012 R2, RT/RT 8.1).
- Enforce physical port controls and disable or restrict USB mass storage where operationally feasible.
- Restrict physical access to endpoints and servers to trusted personnel.
- Monitor for and block unauthorized USB device connections via endpoint controls.
- Verify patch status against the CISA KEV due date (2022-06-15) for any remaining unpatched systems.
Detection
- Monitor Windows event logs for unexpected Mount Manager or device installation activity tied to removable media.
- Alert on new USB device connections on sensitive hosts outside approved change windows.
- Track process creation events originating shortly after USB insertion for suspicious child processes.
- Audit endpoints for missing MS15-085 patches using vulnerability or patch management tooling.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-1769 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Windows Mount Manager Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://blogs.technet.com/b/srd/archive/2015/08/11/defending-against-cve-2015-1769-a-logical-issue-exploited-via-a-malici | Vendor Advisory |
| http://www.securitytracker.com/id/1033244 | Third Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-085 | PatchVendor Advisory |
| http://blogs.technet.com/b/srd/archive/2015/08/11/defending-against-cve-2015-1769-a-logical-issue-exploited-via-a-malici | Vendor Advisory |
| http://www.securitytracker.com/id/1033244 | Third Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-085 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1769 | US Government Resource |
Track CVE-2015-1769 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1769), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.