target entity

Win32k

25 source-linked records in the current knowledge graph.

high

CVE-2018-8589: Microsoft Win32k Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system. Required action: Apply updates per vendor instructions.

CVE-2018-8589EPSS 3.0%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2013-3660: Microsoft Win32k Privilege Escalation Vulnerability

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges. Required action: Apply updates per vendor instructions.

CVE-2013-3660EPSS 39.6%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2015-1701: Microsoft Win32k Privilege Escalation Vulnerability

An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. Required action: Apply updates per vendor instructions.

CVE-2015-1701EPSS 56.2%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2016-7255: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2016-7255EPSS 81.0%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0803: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2019-0803EPSS 45.2%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0797: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2019-0797EPSS 1.9%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1054: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2020-1054EPSS 52.8%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0808: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2019-0808EPSS 53.3%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution