Vulnerability record · CVE-2015-2546 · published 9 September 2015
CVE-2015-2546: Microsoft Windows Win32k kernel driver memory corruption privilege escalation
Microsoft · Windows 10 1507
The Windows kernel-mode Win32k driver mishandles memory, allowing a local user to corrupt memory and elevate privileges through a crafted application. It affects a broad set of older Windows client and server releases and is listed in CISA KEV, so it matters for any environment still running those platforms.
Description
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Automated analysis
high priorityIt is a KEV-listed, actively exploited local privilege escalation with high CVSS impact, though it requires local access and user interaction and affects largely legacy Windows versions.
What it is
The Windows kernel-mode Win32k driver mishandles memory, allowing a local user to corrupt memory and elevate privileges through a crafted application. It affects a broad set of older Windows client and server releases and is listed in CISA KEV, so it matters for any environment still running those platforms.
Impact
An attacker who can run code locally gains elevated privileges on the host, typically SYSTEM, enabling full control of the machine.
Attack surface
Reached locally by executing a crafted application on the target host; the CVSS vector requires low privileges and user interaction, so some form of local access and a user action are needed.
Exploitation
CISA KEV lists it as exploited in the wild with known ransomware campaign use, and EPSS gives a 30-day probability of about 10.2 percent (95th percentile).
What to do
- Apply the Microsoft MS15-097 security update to all affected Windows versions; this is the primary fix.
- Retire or isolate unsupported end-of-life systems such as Vista, Windows 7, Windows 8/8.1 and Windows RT that cannot be patched.
- Restrict local logon and application execution rights so untrusted users cannot run arbitrary binaries on sensitive hosts.
- Enforce least privilege and application allowlisting to block execution of unknown crafted applications.
- Monitor KEV remediation deadlines and confirm patched status across the estate.
Detection
- Alert on unexpected privilege escalation or SYSTEM-level process creation from user-writable paths.
- Monitor for known Win32k exploitation artifacts and suspicious local process token changes.
- Correlate endpoint telemetry for crafted application execution followed by kernel memory corruption indicators.
- Audit hosts still running affected Windows builds against patch inventory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-2546 to the Known Exploited Vulnerabilities catalog on 15 March 2022 as "Microsoft Win32k Memory Corruption Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 5 April 2022.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/76608 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1033485 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-097 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/76608 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1033485 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-097 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2546 | US Government Resource |
Track CVE-2015-2546 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-2546), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.