Home Microsoft CVE-2015-0016
CRITICAL: THIS VULNERABILITY IS ACTIVELY BEING EXPLOITED IN THE WILD (CISA KEV CATALOG)
Back to Microsoft

CVE-2015-0016

Exploited

Windows - TS WebProxy

Microsoft CVSS 7.8 Updated April 30, 2026

Executive Risk Summary

"A directory traversal vulnerability in the TS WebProxy component of Microsoft Windows allows remote attackers to gain privileges via a crafted pathname in an executable file. This vulnerability can be exploited to transition from Low Integrity to Medium Integrity, potentially leading to further exploitation."

Anticipated Attack Path

  1. 1. Initial exploitation of the directory traversal vulnerability
  2. 2. Escalation of privileges from Low Integrity to Medium Integrity
  3. 3. Potential further exploitation of the system

Am I Vulnerable?

  • Verify the presence of the TS WebProxy component
  • Check for the existence of crafted executable files
  • Monitor system logs for suspicious activity

Operational Audit Arsenal

Target Type Service
Target Asset TSWebProxy
Standard Path C:\Windows\System32\tswebproxy.dll
PowerShell
# 🛠️ Senior Engineer Universal Audit
# Target: TSWebProxy (Service)
$Targets = 'TSWebProxy'
$SearchPaths = @("$env:windir\System32", "$env:ProgramFiles", "${env:ProgramFiles(x86)}")

Get-ChildItem -Path $SearchPaths -Include $Targets -Recurse -ErrorAction SilentlyContinue | 
Select-Object FullName, @{Name="Version";Expression={$_.VersionInfo.ProductVersion}}

Patch Impact Forecast

Reboot Required Likely

Potential disruption to Remote Desktop Services

Internal Work Notes

CVE-2015-0016: Directory Traversal Elevation of Privilege Vulnerability in Windows TS WebProxy component. Apply MS15-004 patch to mitigate.

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Official Advisoryhttp://blog.trendmicro.com/trendlabs-security-intelligence/cve-2015-0016-escaping-the-internet-explorer-sandbox/
Official Advisoryhttp://packetstormsecurity.com/files/130201/MS15-004-Microsoft-Remote-Desktop-Services-Web-Proxy-IE-Sandbox-Escape.html
Official Advisoryhttp://secunia.com/advisories/62076
Official Advisoryhttp://www.exploit-db.com/exploits/35983
Official Advisoryhttp://www.securityfocus.com/bid/71965
Official Advisoryhttp://www.securitytracker.com/id/1031524
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-004
Official Advisoryhttps://exchange.xforce.ibmcloud.com/vulnerabilities/99515
Official Advisoryhttps://exchange.xforce.ibmcloud.com/vulnerabilities/99516
Official Advisoryhttp://blog.trendmicro.com/trendlabs-security-intelligence/cve-2015-0016-escaping-the-internet-explorer-sandbox/
Official Advisoryhttp://packetstormsecurity.com/files/130201/MS15-004-Microsoft-Remote-Desktop-Services-Web-Proxy-IE-Sandbox-Escape.html
Official Advisoryhttp://secunia.com/advisories/62076
Official Advisoryhttp://www.exploit-db.com/exploits/35983
Official Advisoryhttp://www.securityfocus.com/bid/71965
Official Advisoryhttp://www.securitytracker.com/id/1031524
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-004
Official Advisoryhttps://exchange.xforce.ibmcloud.com/vulnerabilities/99515
Official Advisoryhttps://exchange.xforce.ibmcloud.com/vulnerabilities/99516
Official Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-0016

Related Microsoft Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.