Vulnerability record · CVE-2015-6132 · published 9 December 2015
CVE-2015-6132: Windows library loading flaw allows local privilege escalation
Microsoft · Windows 10
Microsoft Windows mishandles library loading, letting a local user load a crafted library and gain elevated privileges. The flaw affects a broad set of Windows client and server releases from Vista through Windows 10 1511. Because it yields full control of confidentiality, integrity and availability, it is a serious local escalation primitive.
Description
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability."
AV:L/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityLocal privilege escalation to full system control with a public exploit and very high EPSS, though it requires local code execution and is not in KEV.
What it is
Microsoft Windows mishandles library loading, letting a local user load a crafted library and gain elevated privileges. The flaw affects a broad set of Windows client and server releases from Vista through Windows 10 1511. Because it yields full control of confidentiality, integrity and availability, it is a serious local escalation primitive.
Impact
An attacker who can run code on a host gains SYSTEM-level privileges, enabling full control of the machine, persistence and lateral movement.
Attack surface
Reached locally by executing a crafted application on the target host; the CVSS vector AV:L/AC:L/Au:N indicates no authentication and no user interaction beyond running the attacker's program.
Exploitation
Not listed in CISA KEV, but a public Exploit-DB entry (38968) exists and EPSS is very high at 0.847 (99.7th percentile), so exploitation is practical and likely.
What to do
- Apply Microsoft security bulletin MS15-132 for all affected Windows versions.
- Restrict local interactive logon and execution rights to trusted users only.
- Enable Safe DLL search mode and review insecure library search paths in applications.
- Run untrusted applications in a sandbox or low-privilege context.
- Monitor and remove unnecessary local accounts that could be used to trigger the flaw.
Detection
- Alert on processes loading DLLs from user-writable directories such as temp or user profile paths.
- Monitor for unexpected privilege escalation to SYSTEM by non-service processes.
- Hunt for execution of known Exploit-DB 38968 artifacts or related binaries.
- Audit application directory and PATH entries for writable locations that could host a malicious library.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securitytracker.com/id/1034338 | Third Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-132 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/38968/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1034338 | Third Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-132 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/38968/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2015-6132 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-6132), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.