CVE-2015-2360
published 2015-06-10CVE-2015-2360: win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1…
PriorityP179high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
14.96%
96.3th percentile
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2003 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2015-2360 was actively exploited in the wild by the Duqu 2.0 advanced malware campaign, attributed to a nation-state actor, targeting Windows kernel via win32k.sys ↗
- →The vulnerability resides in win32k.sys (kernel-mode driver); monitor for local privilege escalation attempts or memory corruption events originating from win32k.sys ↗
- →Exploitation vector is a crafted local application; alert on anomalous local process interactions with win32k.sys kernel-mode driver ↗
- ·Duqu 2.0 incorporated several new features beyond the original 2011 Duqu malware; detection signatures for original Duqu may not cover Duqu 2.0 variants exploiting this CVE ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Windows up to Vista Kernel Mode Driver win32k.sys resource management (MS15-061 / EUVD-2015-2453)
vuldb·2026-04-22·CVSS 8.8
CVE-2015-2360 [HIGH] Microsoft Windows up to Vista Kernel Mode Driver win32k.sys resource management (MS15-061 / EUVD-2015-2453)
A vulnerability marked as problematic has been reported in Microsoft Windows up to Vista. This vulnerability affects unknown code in the library win32k.sys of the component Kernel Mode Driver. This manipulation causes improper resource management.
This vulnerability appears as CVE-2015-2360. The attack requires local access. In addition, an exploit is available.
It is suggested to install a patch to address this issue.
GHSA
GHSA-259r-5hvg-4f6x: win32k
ghsa_unreviewed·2022-05-14
CVE-2015-2360 [HIGH] CWE-119 GHSA-259r-5hvg-4f6x: win32k
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
VulnCheck
Microsoft Win32k Privilege Escalation Vulnerability
vulncheck·2015·CVSS 8.8
CVE-2015-2360 [HIGH] CWE-119 Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k Privilege Escalation Vulnerability
Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).
Affected: Microsoft Win32k
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07205202/The_Mystery_of_Duqu_2_0_a_sophisticated_cyberespionage_actor_returns.pdf; https://www.dropbox.com/s/buxkfotx1kei0ce/Whitepaper%20Shadow%20Broker%20-%20Equation%20Group%20Hack.pdf?dl=0; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-06-15
CISA
Microsoft Win32k Privilege Escalation Vulnerability
cisa·2022-05-25·CVSS 8.8
CVE-2015-2360 [HIGH] CWE-119 Microsoft Win32k Privilege Escalation Vulnerability
Vulnerability: Microsoft Win32k Privilege Escalation Vulnerability
Affected: Microsoft Win32k
Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-2360
Remediation Due Date: 2022-06-15
No detection rules found.
No public exploits indexed.
Qualys
Patch Tuesday June 2015 - Update | Qualys
blogs_qualys·2015-06-09·CVSS 8.8
CVE-2015-2360 [HIGH] Patch Tuesday June 2015 - Update | Qualys
Update: Eugene Kaspersky (@e_kaspersky) just blogged about an advanced malware that attacked his company (and a number of others) using a Windows Kernel vulnerability CVE-2015-2360, which Microsoft addressed this month in MS15-061. He calls the malware Duqu 2.0 and affirms that it is backed by a nation state, due to characteristics of the malware’s code. The code bears resemblance to Duqu and incorporates several new features that show that it has received development efforts since the initial version in 2011. There is more information forthcoming – we will update this blog post when that happens. In the meantime make sure you apply MS15-061 to all of your Windows machines.
Original: Patch Tuesday June 2015 – halfway through the year and this month we have eight bulletins bringing the tot
Qualys
Patch Tuesday June 2015 - Update | Qualys
blogs_qualys·2015-06-09·CVSS 8.8
CVE-2015-2360 [HIGH] Patch Tuesday June 2015 - Update | Qualys
Update: Eugene Kaspersky (@e_kaspersky) just blogged about an advanced malware that attacked his company (and a number of others) using a Windows Kernel vulnerability CVE-2015-2360, which Microsoft addressed this month in MS15-061. He calls the malware Duqu 2.0 and affirms that it is backed by a nation state, due to characteristics of the malware’s code. The code bears resemblance to Duqu and incorporates several new features that show that it has received development efforts since the initial version in 2011. There is more information forthcoming – we will update this blog post when that happens. In the meantime make sure you apply MS15-061 to all of your Windows machines.
Original : Patch Tuesday June 2015 – halfway through the year and this month we have eight bulletins bringing the to
Bugzilla
CVE-2015-3258 cups-filters: texttopdf heap-based buffer overflow
bugzilla·2015-06-24·CVSS 7.5
CVE-2015-3258 [HIGH] CVE-2015-3258 cups-filters: texttopdf heap-based buffer overflow
CVE-2015-3258 cups-filters: texttopdf heap-based buffer overflow
A heap-based buffer overflow was discovered in the way the texttopdf utility of cups-filters processed print jobs with a specially crafted line size. An attacker being able to submit print jobs could exploit this flaw to crash texttopdf or, possibly, execute arbitrary code with the privileges of the 'lp' user.
Acknowledgements:
This issue was discovered by Petr Sklenar of Red Hat.
Discussion:
Patch:
https://bugzilla.redhat.com/attachment.cgi?id=993617&action=diff
---
Public via/Patch:
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7363
Fixed in cups-filters 1.0.70.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2015:2360 https://rhn.r
http://www.securityfocus.com/bid/75025http://www.securitytracker.com/id/1032525https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-061http://www.securityfocus.com/bid/75025http://www.securitytracker.com/id/1032525https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-061https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2360
2015-06-10
Published
2022-05-25
Added to CISA KEV
Exploited in the wild