Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka “Win32k Elevation of Privilege Vulnerability.”
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1701
Reference (s):
- BID:74245
- URL: http://www.securityfocus.com/bid/74245
- EXPLOIT-DB:37049
- URL: https://www.exploit-db.com/exploits/37049/
- EXPLOIT-DB:37367

