CISA Known Exploited Vulnerability

CVE-2015-1701 Ransomware

Microsoft · Win32k

Microsoft Win32k Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-264
Ransomware Known

CISA description

An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.

Required action

Apply updates per vendor instructions.