CVE-2015-2546

high-risk
Published 2015-09-09

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.

Do I need to act?

!
39.8% chance of exploitation in next 30 days
EPSS score — higher than 60% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.2/10 High
LOCAL / LOW complexity

Affected Vendors

66
/ 100
high-risk
Severity 25/34 · High
Exploitability 24/34 · High
Exposure 17/34 · Moderate