ZeroHour

CVE-2014-4113

KEVmass

Local Privilege Escalation in Microsoft Win32k Kernel Component (CVE-2014-4113)

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS
EPSS
87%p100
Published
KEV added
AI analysis

CVE-2014-4113 is a privilege escalation flaw (CWE-264) in Win32k, the kernel-mode component of Microsoft Windows; Microsoft's description is unspecified, but the flaw allows an attacker to gain elevated privileges on the host. It is triggered by executing a specially crafted application locally on an affected system, typically by an attacker who has already obtained a foothold with limited user rights. Successful exploitation yields higher-privilege (kernel/administrator-level) execution, letting the attacker fully compromise the machine and evade user-level restrictions — a common second stage chained after an initial intrusion. Any Microsoft Windows system of the era whose Win32k component was not patched by Microsoft's October 2014 security updates is affected. Exploitation is confirmed: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-04), carries a very high EPSS score (87%, ~100th percentile), and public reporting has tied it to threat-actor activity (APT3's Operation Double Tap); no public PoC is catalogued.

What to do: Apply Microsoft's October 2014 security updates — or any later cumulative/rollup updates — on all Windows systems, per CISA's required action, prioritizing internet-exposed and high-value hosts listed in the KEV catalog. Confirm the patched Win32k file version on legacy machines that may have missed these updates. Because this is a local privilege escalation typically chained after an initial foothold, also restrict local execution of untrusted code and limit user privileges on any systems that cannot be patched.

Affected
Microsoft Win32k (kernel-mode component shipping with Microsoft Windows client and server operating systems)
Estimated exposure
masshundreds of millions of Windows installations of the affected era (Win32k ships with every Windows client/server OS of that period); the count of… — Because Win32k is a core component of all Windows operating systems of the era rather than an optional add-on, plausibly affected exposure is bounded only by the Windows installed base at the time, with residual risk limited to machines…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Win32k
Weakness
CWE-264

In the news