CVE-2015-1701: Microsoft Win32k Privilege Escalation Vulnerability
An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.
Other sources
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict local interactive logon and physical access to affected Windows hosts to trusted administrators only; deny or heavily limit use of unprivileged and guest accounts on those systems.
- Compensating control
Implement application control/whitelisting (for example AppLocker or Software Restriction Policies) to prevent execution of untrusted or crafted applications by non‑administrative users on affected systems.
- Operational
Remove local administrator privileges from user accounts that do not require them (apply principle of least privilege) to reduce the impact of a local privilege‑escalation exploit.
- Operational
Monitor event logs, endpoint protection alerts, and intrusion detection systems for indicators of local privilege escalation or unexpected code execution on affected hosts and investigate/remediate any suspicious activity.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1701?
CVE-2015-1701 is considered a high-severity vulnerability that allows local attackers to execute arbitrary code with elevated privileges.
How do I fix CVE-2015-1701?
To mitigate CVE-2015-1701, it is recommended to apply the latest security updates provided by Microsoft for the affected operating systems.
Which systems are affected by CVE-2015-1701?
CVE-2015-1701 affects Microsoft Windows Server 2003 SP2, Windows Vista SP2, and Windows Server 2008 SP2.
What is the attack vector for CVE-2015-1701?
The attack vector for CVE-2015-1701 is local, meaning that an attacker must have local access to the affected system to exploit the vulnerability.
Can CVE-2015-1701 be exploited remotely?
No, CVE-2015-1701 requires local access to exploit, so it cannot be exploited remotely without physical access to the system.