CVE-2015-2360
KEVmassWin32k Local Privilege Escalation in Microsoft Windows Kernel Drivers
CISA: Microsoft Win32k Privilege Escalation Vulnerability
CVE-2015-2360 is a memory-handling flaw (CWE-119) in Win32k.sys, the Windows kernel-mode driver, that allows a local user to elevate privileges or cause a denial-of-service crash. It is triggered by local code that drives Win32k into improperly handling objects in memory, letting the attacker run code with kernel/SYSTEM-level rights — typically chained with a separate remote code execution bug to go from network access to full system compromise. Any Microsoft Windows system that has not received the vendor fix is affected, and because the fix shipped in mid-2015, the remaining exposed population is largely legacy Windows deployments that missed regular patching. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-25, indicating exploitation in the wild, and EPSS assigns a 15% probability of exploitation within 30 days (96th percentile); no public proof-of-concept is known.
What to do: Apply the Microsoft update from security Bulletin MS15-078 (July 2015) to any Windows system lacking it, prioritizing internet-facing hosts running legacy Windows/Server releases and POS, embedded or air-gapped systems that miss routine patch cycles. Verify via patch inventory that the affected Win32k.sys builds are current, and treat the CISA KEV listing as mandatory remediation per the required action (apply updates per vendor instructions).
| Microsoft Win32k.sys / Windows kernel-mode drivers (Microsoft Windows) | All supported Windows releases of the era — Windows Vista SP2, Windows 7 SP1, Windows 8, Windows 8.1, Windows RT 8.1, Windows Server 2008 SP2, Server 2008 R2 SP |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Win32k
- Weakness
- CWE-119