CVE-2015-1701

Description

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka Win32k Elevation of Privilege Vulnerability.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
90.175

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows Server 2003 (KB3045171)Windows
Security Update for Windows Vista (KB3045171)Windows
Security Update for Windows Server 2008 (KB3045171)Windows
Security Update for Windows 7 (KB3045171)Windows
Security Update for Windows 8 (KB3045171)Windows
Security Update for Windows 8.1 (KB3045171)Windows
Security Update for Windows Server 2003 x64 Edition (KB3045171)Windows
Security Update for Windows Vista for x64-based Systems (KB3045171)Windows
Security Update for Windows Server 2008 x64 Edition (KB3045171)Windows
Security Update for Windows 7 for x64-based Systems (KB3045171)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB3045171)Windows
Security Update for Windows 8 for x64-based Systems (KB3045171)Windows
Security Update for Windows Server 2012 (KB3045171)Windows
Security Update for Windows 8.1 for x64-based Systems (KB3045171)Windows
Security Update for Windows Server 2012 R2 (KB3045171)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-17781Security Update for Windows Server 2003 (KB3045171)
PATCH-17782Security Update for Windows Vista (KB3045171)
PATCH-17783Security Update for Windows Server 2008 (KB3045171)
PATCH-17784Security Update for Windows 7 (KB3045171)
PATCH-17785Security Update for Windows 8 (KB3045171)
PATCH-17786Security Update for Windows 8.1 (KB3045171)
PATCH-17787Security Update for Windows Server 2003 x64 Edition (KB3045171)
PATCH-17788Security Update for Windows Vista for x64-based Systems (KB3045171)
PATCH-17789Security Update for Windows Server 2008 x64 Edition (KB3045171)
PATCH-17790Security Update for Windows 7 for x64-based Systems (KB3045171)
PATCH-17791Security Update for Windows Server 2008 R2 x64 Edition (KB3045171)
PATCH-17792Security Update for Windows 8 for x64-based Systems (KB3045171)
PATCH-17793Security Update for Windows Server 2012 (KB3045171)
PATCH-17794Security Update for Windows 8.1 for x64-based Systems (KB3045171)
PATCH-17795Security Update for Windows Server 2012 R2 (KB3045171)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234