CVE-2015-2367: Infoleak
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from uninitialized kernel memory via a crafted application, aka "Win32k Information Disclosure Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2367?
CVE-2015-2367 is classified as a moderate severity vulnerability.
How do I fix CVE-2015-2367?
To fix CVE-2015-2367, apply the relevant Microsoft security updates provided in MS15-073.
What software versions are affected by CVE-2015-2367?
CVE-2015-2367 affects multiple versions of Microsoft Windows, including Windows 2003, Vista, Server 2008, 7, 8, 8.1, and 2012.
What type of vulnerability is CVE-2015-2367?
CVE-2015-2367 is a local information disclosure vulnerability in the win32k.sys driver.
Can CVE-2015-2367 be exploited remotely?
No, CVE-2015-2367 requires local access to the affected system to be exploited.