Vulnerability record · CVE-2015-2360 · published 10 June 2015
CVE-2015-2360: Microsoft Windows win32k.sys memory corruption privilege escalation
Microsoft · Windows 7
win32k.sys in the Windows kernel-mode drivers mishandles memory, allowing a local user to corrupt memory through a crafted application. The flaw is a buffer overflow/use-after-free class issue that lets a low-privileged local user escalate to kernel-level privileges or crash the system. It affects a broad set of older Windows client and server releases.
Description
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is a kernel privilege escalation with known exploitation per CISA KEV, though it requires local access and affects only legacy Windows versions.
What it is
win32k.sys in the Windows kernel-mode drivers mishandles memory, allowing a local user to corrupt memory through a crafted application. The flaw is a buffer overflow/use-after-free class issue that lets a low-privileged local user escalate to kernel-level privileges or crash the system. It affects a broad set of older Windows client and server releases.
Impact
An attacker who can run code locally gains elevated privileges, typically SYSTEM, on the affected host. Alternatively, the same memory corruption can be used to cause a denial of service.
Attack surface
Reached locally by executing a crafted application on the target machine; no user interaction beyond running the program is required, and the attacker needs only low privileges. The CVSS vector lists network access, but the description and flaw type are local privilege escalation.
Exploitation
CVE-2015-2360 is listed in CISA KEV with a 2022-06-15 remediation due date, indicating known exploitation in the wild. EPSS gives a 30-day probability of about 0.15 (96th percentile), and no ransomware campaign use is recorded.
What to do
- Apply the Microsoft MS15-061 security update to all affected Windows versions.
- Prioritize patching of Windows 7, 8, 8.1, RT, Server 2003, 2008, and 2012 systems still in service.
- Restrict local interactive logon and application execution to trusted users where feasible.
- Retire or isolate end-of-life platforms that no longer receive security updates.
Detection
- Monitor for unexpected processes gaining SYSTEM or kernel-level privileges on affected hosts.
- Alert on crashes or bugchecks originating from win32k.sys.
- Track execution of unsigned or newly written binaries by low-privileged users on legacy Windows systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-2360 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Win32k Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/75025 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1032525 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-061 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/75025 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1032525 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-061 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2360 | US Government Resource |
Track CVE-2015-2360 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-2360), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.