← Vulnerability feed

Vulnerability record · CVE-2015-6133 · published 9 December 2015

CVE-2015-6133: Windows library loading flaw allows local privilege escalation

Microsoft · Windows 10

Microsoft Windows 8, 8.1, RT, Server 2012 Gold/R2, and Windows 10 Gold/1511 mishandle library loading, letting a local user run code with elevated privileges via a crafted application. The flaw is a permissions/access-control weakness in how libraries are resolved, and it matters because it turns local access into full system compromise on unpatched hosts.

7.2 CVSS 2.0 High EPSS 67% · top 0.7% CWE-264 · Permissions and access controls
7.2CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability."

AV:L/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityLocal privilege escalation to full system control with a high EPSS score, though exploitation requires prior local code execution and no KEV listing exists.

What it is

Microsoft Windows 8, 8.1, RT, Server 2012 Gold/R2, and Windows 10 Gold/1511 mishandle library loading, letting a local user run code with elevated privileges via a crafted application. The flaw is a permissions/access-control weakness in how libraries are resolved, and it matters because it turns local access into full system compromise on unpatched hosts.

Impact

An attacker who can run a crafted application on the target gains complete control of confidentiality, integrity and availability (CVSS 2.0 base 7.2, C:C/I:C/A:C), effectively escalating to administrative or SYSTEM-level privileges.

Attack surface

Reached locally: the vector is AV:L with AC:L and Au:N, so no network exposure and no authentication are required, but the attacker must already be able to execute a crafted application on the machine. No user interaction beyond running that application is implied by the record.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high (0.66581, 99.25th percentile), indicating elevated predicted exploitation likelihood; references are patch and advisory entries only, with no public exploit tag.

What to do

  • Apply the Microsoft MS15-132 security update on all affected Windows 8, 8.1, RT, Server 2012 Gold/R2, and Windows 10 Gold/1511 systems.
  • Restrict who can execute untrusted binaries on endpoints and servers, since exploitation requires local code execution.
  • Enforce least privilege so standard users cannot run arbitrary crafted applications, and remove unnecessary local admin rights.
  • Retire or isolate end-of-life builds (Windows 8, RT Gold, Windows 10 Gold/1511) that no longer receive security fixes.

Detection

  • Monitor for unexpected processes loading DLLs from user-writable or non-standard directories, especially around privilege escalation.
  • Alert on child processes spawned from user-writable paths that run with elevated or SYSTEM tokens.
  • Audit application execution on affected hosts for unsigned or newly appeared binaries in user profile and temp directories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-6133 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed8.8CVE-2023-21674Windows ALPC use-after-free privilege escalationCVE-2023-21674 is a use-after-free (CWE-416) in the Windows Advanced Local Procedure Call (ALPC) subsystem that allows elevation of privilege. It aff…KEVEPSS 41%analysed8.8CVE-2022-41128Windows Scripting Languages out-of-bounds write allows remote code executionCVE-2022-41128 is an out-of-bounds write (CWE-787) in Windows Scripting Languages that leads to remote code execution. Microsoft rates it 8.8 HIGH wi…KEVEPSS 25%analysed8.8CVE-2022-26923Microsoft Active Directory Domain Services certificate validation privilege escalationActive Directory Domain Services fails to properly validate certificate attributes, allowing a low-privileged domain user to obtain a certificate tha…KEVEPSS 84%analysed8.8CVE-2021-40444Microsoft MSHTML remote code execution via malicious Office documentCVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX…KEVEPSS 97%analysed8.8CVE-2021-34527Windows Print Spooler privileged file operation RCE (PrintNightmare)The Windows Print Spooler service improperly performs privileged file operations, allowing an attacker to execute arbitrary code as SYSTEM. This is t…KEVEPSS 100%analysed8.8CVE-2020-1020Windows Adobe Type Manager Library font parsing out-of-bounds write RCEMicrosoft Windows Adobe Type Manager Library mishandles a specially crafted multi-master font in Adobe Type 1 PostScript format, causing an out-of-bo…KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2015-6133), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.