7.2
CVSSv2

CVE-2015-2365

Published: 14/07/2015 Updated: 08/05/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 7 -

microsoft windows 8.1 -

microsoft windows server 2012 -

microsoft windows vista

microsoft windows server 2008 -

microsoft windows server 2012 r2

microsoft windows rt -

microsoft windows 2003 server

microsoft windows 2003 server r2

microsoft windows server 2008 r2

microsoft windows 8 -

microsoft windows rt 8.1 -

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=335 Freed memory is accessed after switching between two desktops of which one is closed The testcase crashes with and without special pool enabled The attached crash output is with special enabled on win32ksys and ntoskrnlsys Proof of Concept: githubcom/off ...

Github Repositories

win-kernel-UAFs CVE Project-zero issue Microsoft Patch CVE-2015-2365 335 ms15-073 CVE-2015-2366 339 ms15-073 CVE-2015-2507 433 ms15-097