KEVIntel
7.8
CVSS
High

CVE-2015-1701

PUBLISHED

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges...

Exploited in the wild Used in malware Low complexity No user interaction
Vendor
Microsoft
Product
Windows
Published
Apr 21, 2015
EPSS

Description

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."

windows cisa malware ransomware metasploit

CVSS scores

CVSS v3.1 7.8 High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 7.2

AV:L/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2022-03-03 00:00:00 UTC · Source

Used in malware

Recorded 2022-03-03 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 03, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

ms15_051_client_copy_image

metasploit · Created Unknown

Metasploit module for CVE-2015-1701

Anonymous-Family/CVE-2015-1701-download

github · Created 2022-03-21 06:39:18 UTC · 0 stars

Anonymous-Family/CVE-2015-1701

github · Created 2022-03-21 06:26:21 UTC · 0 stars

Unspecified vulnerability in Microsoft Windows before 8 allows local users to gain privileges via unknown vectors, as exploited in the wild in April 2015 (Base Score: 7.2 HIGH) Current Description Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability

hfiref0x/CVE-2015-1701

github · Created 2015-05-12 18:04:48 UTC · 287 stars

Win32k LPE vulnerability used in APT attack

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Metasploit