Junglewise Threat Intelligence

CVE-2014-4113: Microsoft Win32k Privilege Escalation Vulnerability

CVE-2014-4113 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-04

Technologies: Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows 8.1, Microsoft Windows Server 2003, Microsoft Windows Server 2012, Microsoft Win32K, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

The win32k.sys kernel-mode driver in multiple Microsoft Windows operating systems contains a privilege escalation vulnerability. Local users can exploit this via a crafted application to gain elevated privileges on the system.

Affected products

  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8 Gold
  • Microsoft Windows 8.1 Gold
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows RT Gold, 8.1

Timeline

  • 2014-10-14: advisory: Microsoft Security Bulletin MS14-058 published.
  • 2014-10: exploited: Exploitation in the wild reported.
  • 2022-05-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats