← back
CVE-2015-2546

CVE-2015-2546

CVSS 8.2 HIGHEPSS 10.9%● KEVCWE-119
In short

A flaw in Windows kernel-mode driver allows a locally logged-in user to run malicious code with system privileges. An attacker needs to already have access to the computer and can exploit this to take complete control.

Technical detail

CWE-119 memory corruption vulnerability in Win32k kernel-mode driver exploitable via crafted application; requires local user access; successful exploitation results in privilege escalation to kernel level, enabling arbitrary code execution with SYSTEM privileges.

Summary generated and translated by AI from the official description.
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →