Executive brief
The win32k.sys kernel-mode driver in multiple Microsoft Windows operating systems contains a privilege escalation vulnerability. Local users can exploit this via a crafted application to gain elevated privileges on the system.
Affected products
- Microsoft Windows Server 2003 SP2
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Windows 8 Gold
- Microsoft Windows 8.1 Gold
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows RT Gold, 8.1
Timeline
- 2014-10-14: advisory: Microsoft Security Bulletin MS14-058 published.
- 2014-10: exploited: Exploitation in the wild reported.
- 2022-05-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.