CVE-2014-4076
65Vexday Risk Score
Patch now. It exploitation observed by VulnCheck, has a working public exploit and 1 threat group(s) use it.
ssvc Actepss 23%
from disclosure to weapon79 days
Published on NVDNov 11
1st PoC+79d
metasploitNov 11
VulnCheck+632d
exploitation probability
23%top 2% of all CVEs
observed exploitation
yesVulnCheck
1 group(s)6 public exploit(s)
Who exploits it — 1
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2) tcpip6.sys, aka "TCP/IP Elevation of Privilege Vulnerability."
Affected products
n/a · n/apublic PoCs found — 6
exploitdbwww.exploit-db.com/exploits/35936unverifiedexploitdbwww.exploit-db.com/exploits/37755unverifiedgithubgithub.com/fungoshacks/CVE-2014-4076★ 0cve_referencewww.exploit-db.com/exploits/37755/unverifiedcve_referencewww.exploit-db.com/exploits/35936unverifiedvulncheckvulncheck.com/xdb/ea8c478978c8unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.