VDB
CVE-2015-1701
CVE-2015-1701
PUBLISHED
KEV
CVSS 7.199999809265137 HIGH
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."
EPSS 56.20% · 99.0th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
56.20%
99.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_2003_server | r2 |
| n/a | n/a | n/a |
| microsoft | windows_server_2008 | |
| microsoft | windows_vista | |
| microsoft | windows_7 |
Timeline
- Jan 1, 1 VulnCheck XDB Entry
- Jan 19, 1970 VulnCheck XDB Entry
- Jan 19, 1970 VulnCheck XDB Entry
- Oct 14, 2014 VulnCheck KEV Exploitation
- Oct 15, 2014 VulnCheck KEV Exploitation
- Dec 22, 2014 VulnCheck KEV Exploitation
- Jan 6, 2015 VulnCheck KEV Exploitation
- Feb 1, 2015 VulnCheck KEV Exploitation
- Feb 6, 2015 VulnCheck KEV Exploitation
- Apr 9, 2015 VulnCheck KEV Exploitation
- Apr 13, 2015 VulnCheck KEV Exploitation
- Apr 18, 2015 VulnCheck KEV Exploitation
References
- 74245 vdb
- MS15-051 vendor-advisory
- 1032155 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2015-1701 advisory
- https://www.exploit-db.com/exploits/37049 url
- https://www.exploit-db.com/exploits/37367 url
- http://seclists.org/fulldisclosure/2020/May/34 mailing_list
- http://twitter.com/symantec/statuses/590208710527549440 technical
- https://www.exploit-db.com/exploits/37049/ exploit
- https://www.exploit-db.com/exploits/37367/ exploit
- https://www.fireeye.com/blog/threat-research/2015/04/probable_apt28_useo.html advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1701 technical