CVE-2015-2546
high-risk
Published 2015-09-09
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.
Do I need to act?
!
39.8% chance of exploitation in next 30 days
EPSS score — higher than 60% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.2/10
High
LOCAL
/ LOW complexity
Affected Products (12)
Affected Vendors
References (7)
Third Party Advisory
http://www.securityfocus.com/bid/76608
Third Party Advisory
http://www.securitytracker.com/id/1033485
Third Party Advisory
http://www.securityfocus.com/bid/76608
Third Party Advisory
http://www.securitytracker.com/id/1033485
66
/ 100
high-risk
Severity
25/34 · High
Exploitability
24/34 · High
Exposure
17/34 · Moderate