← Back to CVE List
Vulnerability Intelligence Report
Microsoft Win32k Memory Corruption Vulnerability

CVE-2015-2546

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.2
HIGH
Exploitability:1.5
Impact Score:6.1
EPSS Probability:10.93%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-119 ↗CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

Affected Products & Versions

Vendor Product Affected Versions
n/a n/a n/a (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
10.929%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2015-03-19T00:00:00
Published2015-09-09T00:00:00
Patch Date2015-09-08
Last Updated2026-08-14T03:55:43

LINK COPIED TO CLIPBOARD