Vulnerability record · CVE-2015-6175 · published 9 December 2015
CVE-2015-6175: Windows 10 Kernel Memory Elevation of Privilege
Microsoft · Windows 10 1507
The Windows 10 kernel fails to properly handle memory, letting a local user run a crafted application to gain elevated privileges. It matters because a low-privileged local attacker can reach full system rights, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with confirmed KEV listing and known exploitation, though it is a local privilege escalation requiring user interaction on an old Windows 10 build.
What it is
The Windows 10 kernel fails to properly handle memory, letting a local user run a crafted application to gain elevated privileges. It matters because a low-privileged local attacker can reach full system rights, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker who runs the crafted application gains high confidentiality, integrity and availability impact, effectively obtaining kernel-level privileges on the host.
Attack surface
Reached locally by running a crafted application on the target machine; the CVSS vector requires user interaction (UI:R) and no prior privileges (PR:N). No remote or network path is described.
Exploitation
CISA added it to KEV on 2022-05-25 with a 2022-06-15 remediation due date, indicating known exploitation; EPSS 30-day probability is about 5.2 percent (92nd percentile). No ransomware campaign use is recorded.
What to do
- Apply the Microsoft MS15-135 security update for Windows 10 Gold (1507) as the first action.
- Restrict and monitor execution of untrusted applications on Windows 10 1507 endpoints.
- Remove or upgrade unsupported Windows 10 1507 systems that cannot receive current patches.
- Enforce least privilege so standard users cannot run arbitrary local code where avoidable.
Detection
- Monitor for unexpected privilege escalation or token manipulation events in Windows security logs on Windows 10 1507 hosts.
- Alert on execution of unsigned or newly seen binaries from user-writable paths that subsequently spawn high-integrity processes.
- Hunt for processes gaining SYSTEM or high-integrity tokens shortly after user-launched application execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-6175 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Windows Kernel Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securitytracker.com/id/1034334 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-135 | PatchVendor Advisory |
| http://www.securitytracker.com/id/1034334 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-135 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-6175 | US Government Resource |
Track CVE-2015-6175 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-6175), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.