PoC Index

CVE-2015-2546

KEV RANSOMWAREHIGH 8.2EPSS 10.9%

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.

CVSS v3.1
8.2 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS v2.0
6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS
10.93% chance of exploitation in the next 30 days, 96th percentile
CISA KEV
added 2022-03-15, used in ransomware campaigns
Published
2015-09-09
Updated
2026-08-14

Proof-of-concept exploits (1)

Exploit collections (1)

References

Related