CVE-2015-1701High· 7.8▾ Abyssal⚠ Exploited in the wild0dayPoC availableWin32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of …
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 11.2 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Mar 24, 2022
Last analysed / modified upstream
56%
Exploit-DB · 3 GitHub repos · Metasploit ×1 (last check)
Added to the CISA catalog on Mar 3, 2022. Federal remediation due Mar 24, 2022. View catalog ↗
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."
windows_2003_serverwindows_2003_server = r2windows_7windows_server_2008windows_vistaRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-81963High· 7.8Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2026-83991Medium· 5.5Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
CVE-2026-88097High· 8.1Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
CVE-2026-62874Critical· 10.0Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85878Critical· 9.9Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.