Junglewise Threat Intelligence

CVE-2015-6175: Microsoft Windows Kernel Privilege Escalation Vulnerability

CVE-2015-6175 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Windows, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

A privilege escalation vulnerability exists in the Microsoft Windows kernel that allows local users to gain elevated privileges. An attacker can exploit this by running a specially crafted application to manipulate kernel memory.

Affected products

  • Microsoft Windows 10 Gold (1507)

Timeline

  • 2015-12-08: patched: Microsoft released security bulletin MS15-135.
  • 2015-12-09: disclosed: NVD published the CVE.
  • 2022-05-25: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.

Related threats