CVE-2015-2546highunder attackransomwareCWE-119

CVE-2015-2546

Published · Updated

78Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.2epss 10%
from disclosure to weapon624 days
Published on NVDSep 9
1st PoC+624d
CISA KEV+2379d
exploitation probability
10%top 4% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
Action required by CISAfederal deadline: 2022-04-05

Apply updates per vendor instructions.

In short

A flaw in Windows kernel-mode driver allows a locally logged-in user to run malicious code with system privileges. An attacker needs to already have access to the computer and can exploit this to take complete control.

Technical detail

CWE-119 memory corruption vulnerability in Win32k kernel-mode driver exploitable via crafted application; requires local user access; successful exploitation results in privilege escalation to kernel level, enabling arbitrary code execution with SYSTEM privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.