HTTP: Microsoft Windows CVE-2015-0076 Information Disclosure

This signature detects attempts to exploit a known vulnerability against Microsoft Windows Operating system. A successful attack can lead to unauthorized information disclosure.

Extended Description

The photo-decoder implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly initialize memory for rendering of JXR images, which allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "JPEG XR Parser Information Disclosure Vulnerability."

Affected Products

Microsoft windows_rt_8.1

References

CVE: CVE-2015-0076

Short Name
HTTP:STC:CVE-2015-0076-INF-DSC
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2015-0076 Disclosure Information Microsoft Windows
Release Date
03/10/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Microsoft

CVSS Score

4.3

Found a potential security threat?