CVE-2015-2360

HIGH(8.8)KEVElevated Risk

Microsoft Win32k Privilege Escalation Vulnerability

Description

CVE-2015-2360 is a privilege escalation vulnerability in Win32k.sys, the kernel-mode driver in Microsoft Windows, that allows local users to gain elevated privileges or cause a denial-of-service condition. The vulnerability exists in how Win32k.sys handles objects in kernel memory, and can be exploited by a local attacker running a specially crafted application. Because Win32k.sys operates in the Windows kernel, successful exploitation can grant SYSTEM-level privileges, giving the attacker complete control over the affected system. CISA has listed CVE-2015-2360 in the Known Exploited Vulnerabilities catalog, confirming active exploitation, and its EPSS percentile of 94.0% indicates a very high probability of exploitation activity.

KEV Information

Vendor
Microsoft
Product
Win32k
Date Added
May 25, 2022
Due Date
June 15, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
microsoftwindows 7-
microsoftwindows 8-
microsoftwindows 8.1-
microsoftwindows rt-
microsoftwindows rt 8.1-
microsoftwindows server 2003-; r2
microsoftwindows server 2008-; r2
microsoftwindows server 2012-; r2
microsoftwindows vista-

References

Weakness Type

No specific CWE has been assigned to CVE-2015-2360 in the NVD database. The vulnerability resides in Win32k.sys, the Windows kernel-mode driver responsible for window management and graphics operations. The flaw involves improper handling of objects in kernel memory, which can lead to memory corruption when a crafted application triggers specific kernel code paths. This class of vulnerability in kernel-mode drivers typically relates to use-after-free or improper object lifecycle management in the kernel's user-interface subsystem.

Learn more: CWE Overview

Impact Analysis

CVE-2015-2360 enables local privilege escalation or denial of service through the Win32k.sys kernel-mode driver in Microsoft Windows. The vulnerability requires local access and a crafted application, but no elevated privileges are needed to trigger it. Confidentiality (High): SYSTEM-level privilege escalation grants the attacker access to all data on the system, including protected system files, credentials of other users, and security-sensitive configurations. Integrity (High): With kernel-level access, the attacker can modify any file, install rootkits, alter security settings, and manipulate the operating system at its core. Availability (High): The vulnerability can also trigger a denial-of-service condition, causing a kernel crash (blue screen of death) that renders the system inoperable. With an EPSS percentile of 94.0%, this vulnerability has a very high probability of active exploitation, commonly used as a post-exploitation privilege escalation technique.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2015-2360 by listing it in the Known Exploited Vulnerabilities catalog, with a remediation deadline of June 15, 2022. The EPSS percentile of 94.0% indicates a very high likelihood of exploitation activity. Win32k.sys privilege escalation vulnerabilities are among the most commonly exploited Windows kernel vulnerabilities, routinely used in post-exploitation scenarios where an attacker has gained initial access through another vector and needs to escalate to SYSTEM privileges to achieve full system control, persist across reboots, or bypass security software running at higher privilege levels.

Remediation

  1. Apply Microsoft security updates per vendor instructions as required by the CISA KEV catalog. Install all relevant patches that address CVE-2015-2360 in the Win32k.sys kernel-mode driver.
  2. Ensure all Windows systems are running current, supported versions with the latest security updates. Win32k.sys vulnerabilities are frequently patched in Microsoft's monthly security updates.
  3. Implement least privilege access controls to reduce the impact of privilege escalation. Users should not run with administrative privileges for daily operations, and application whitelisting should prevent unauthorized executables from running.
  4. Deploy endpoint detection and response (EDR) solutions capable of detecting kernel exploitation attempts, unusual privilege changes, and suspicious Win32k.sys-related activity.
  5. Enable Windows Credential Guard and virtualization-based security where supported, which isolates critical system components and credential storage from kernel-level attacks, limiting the impact even if kernel compromise occurs.

Technical Details

CVE-2015-2360 is a kernel-mode privilege escalation vulnerability in Win32k.sys, the Windows kernel-mode driver responsible for the window manager and GDI graphics subsystem. The vulnerability arises from improper handling of objects in kernel memory when processing user-mode requests through the Win32k system call interface. When a local attacker runs a crafted application that triggers specific Win32k code paths, the driver mishandles kernel objects, leading to memory corruption in kernel space. This corruption can be leveraged to overwrite kernel data structures, modify function pointers, or redirect execution flow to attacker-controlled code running at kernel privilege level (Ring 0). Successful exploitation elevates the attacker from a standard user to SYSTEM privileges, the highest local privilege level in Windows. Alternatively, if the memory corruption is not precisely controlled, it may cause a kernel panic (BSOD) resulting in denial of service.

Frequently Asked Questions

Is CVE-2015-2360 being actively exploited?

Yes, CVE-2015-2360 is actively exploited. CISA confirmed its inclusion in the Known Exploited Vulnerabilities catalog with a remediation deadline of June 15, 2022. The EPSS percentile of 94.0% indicates very high exploitation probability.

What products are affected by CVE-2015-2360?

CVE-2015-2360 affects Microsoft Windows through the Win32k.sys kernel-mode driver. Multiple Windows versions are affected. Organizations should consult Microsoft security bulletins for specific affected versions and available patches.

How do I fix CVE-2015-2360?

Apply Microsoft security updates that address this vulnerability in Win32k.sys. Ensure Windows systems are running supported versions with current patches. Implement least privilege access controls and deploy endpoint detection solutions capable of detecting kernel exploitation.

How severe is CVE-2015-2360?

CVE-2015-2360 is a kernel-mode privilege escalation vulnerability with an EPSS percentile of 94.0%. Successful exploitation can grant SYSTEM-level privileges or cause system crashes. Its location in the kernel makes it particularly severe, as kernel-level access allows complete system control and can bypass most security software.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score14.96%
EPSS Percentile96.4%

Dates

PublishedJune 10, 2015
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.