Junglewise Threat Intelligence

CVE-2015-2360: Microsoft Win32k Privilege Escalation Vulnerability

CVE-2015-2360 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Windows Vista, Microsoft Windows 8.1, Microsoft Windows Server 2008, Microsoft Windows Server 2003, Microsoft Windows Server 2012, Microsoft Win32K, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

A memory corruption vulnerability in win32k.sys within the Microsoft Windows kernel-mode driver allows local users to gain elevated privileges or cause a denial of service. The flaw is triggered via a crafted application and has been observed being exploited in the wild.

Affected products

  • Microsoft Windows Server 2003 SP2 and R2 SP2
  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2 and R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8 Gold
  • Microsoft Windows 8.1 Gold
  • Microsoft Windows Server 2012 Gold and R2
  • Microsoft Windows RT Gold and 8.1

Timeline

  • 2015-06-09: advisory: Microsoft Security Bulletin MS15-061 published
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats