Back

CVE-2015-1701

HIGH CISA KEV

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."

Published: Apr 21, 2015 Modified: Apr 22, 2026
NVD-CWE-noinfo

CVSS Metrics

CVSSv3
Attack Vector: LOCAL Attack Complexity: LOW Privileges Required: LOW User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products (5)

Vendor Product Version
microsoft windows_2003_server -
microsoft windows_2003_server r2
microsoft windows_7 -
microsoft windows_server_2008 -
microsoft windows_vista -

GitHub Security Advisory GHSA-rq9p-fw9r-ppg4

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server...

References (17)

Risk Scores

CVSS Score 7.8 / 10
EPSS Score 56.20%

Top 1% most likely to be exploited

Threat Score 78.1 / 100

CISA Known Exploited

Date Added: 2022-03-03
Due Date: 2022-03-24
Required Action:

Apply updates per vendor instructions.

Used in Ransomware Campaigns

Data Sources

NVD CISA KEV EPSS GitHub