Vulnerability record · CVE-2014-4113 · published 15 October 2014
CVE-2014-4113: Microsoft Windows win32k.sys privilege escalation via crafted application
Microsoft · Windows 7
A flaw in the win32k.sys kernel-mode driver in multiple Microsoft Windows versions lets a local user escalate privileges by running a crafted application. It was exploited in the wild in October 2014 and is listed in CISA's Known Exploited Vulnerabilities catalog, so it remains relevant for unpatched legacy systems.
Description
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a confirmed in-the-wild, KEV-listed local privilege escalation with public exploits and a very high EPSS score, though it requires local access and user interaction.
What it is
A flaw in the win32k.sys kernel-mode driver in multiple Microsoft Windows versions lets a local user escalate privileges by running a crafted application. It was exploited in the wild in October 2014 and is listed in CISA's Known Exploited Vulnerabilities catalog, so it remains relevant for unpatched legacy systems.
Impact
An attacker who can run code on a target gains full system privileges, allowing complete control of the host. This typically serves as the elevation step after initial access.
Attack surface
Reached locally by executing a crafted application on the affected system; the CVSS vector indicates no privileges are required but user interaction is needed. No remote or network vector is described.
Exploitation
CISA KEV lists it as exploited in the wild, EPSS is very high (0.87, 99.7th percentile), and multiple references are tagged Exploit, including public Exploit-DB entries.
What to do
- Apply Microsoft security update MS14-058 (KB3000061) to all affected Windows versions.
- Retire or isolate unsupported legacy systems (Windows Server 2003, Vista, Windows 7/8/8.1, RT) that cannot be patched.
- Restrict local interactive logon and application execution to trusted users and signed binaries.
- Monitor for and block known public exploit code for this vulnerability on endpoints.
Detection
- Alert on unexpected elevation of low-privilege processes to SYSTEM, especially via win32k.sys call paths.
- Hunt for known public exploit binaries or hashes associated with CVE-2014-4113 on endpoints.
- Monitor for suspicious TrackPopupMenu-related activity or kernel exploitation artifacts on affected hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-4113 to the Known Exploited Vulnerabilities catalog on 4 May 2022 as "Microsoft Win32k Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 25 May 2022.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-4113 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-4113), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.