First published: Tue Jul 14 2015(Updated: )
win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Win32k Information Disclosure Vulnerability," a different vulnerability than CVE-2015-2381.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 8.0 | ||
Microsoft Windows | ||
Microsoft Windows RT | ||
Microsoft Windows RT | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server | =r2 | |
Microsoft Windows Server | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2382 has been rated as important by Microsoft due to its potential for information disclosure.
To fix CVE-2015-2382, install the security updates provided by Microsoft in the August 2015 security bulletin.
CVE-2015-2382 affects Microsoft Windows 8, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows RT.
CVE-2015-2382 can be exploited by local users through a crafted application to access sensitive kernel memory.
CVE-2015-2382 is a local vulnerability, requiring local user access for exploitation.