win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."
Published Oct 15, 2014 ·Due May 25, 2022
7.8
HIGHCVSS 3.1
EPSS 86.93%
Description
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."
Affected products
No data.
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- r2
- n/a
- r2
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
Date Added
May 4, 2022
Patch Due
May 25, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 10, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 86.93% (0.86928) | 99.74th | v5 (v2026.06.15) |
| Jun 15, 2026 | 86.93% (0.86928) | 99.72th | v5 (v2026.06.15) |
| May 22, 2026 | 78.46% (0.78459) | 99.06th | v4 (v2025.03.14) |
| Aug 24, 2025 | 83.01% (0.83011) | 99.21th | v4 (v2025.03.14) |
| Aug 16, 2025 | 81.98% (0.81983) | 99.15th | v4 (v2025.03.14) |
| Jun 9, 2025 | 78.85% (0.78854) | 98.98th | v4 (v2025.03.14) |
| May 9, 2025 | 77.85% (0.77847) | 98.93th | v4 (v2025.03.14) |
| May 7, 2025 | 80.35% (0.80348) | 99.05th | v4 (v2025.03.14) |
| Mar 17, 2025 | 78.29% (0.78288) | 98.98th | v4 (v2025.03.14) |
| Mar 9, 2025 | 74.95% (0.74950) | 98.44th | v3 (v2023.03.01) |
| Jul 3, 2024 | 67.73% (0.67733) | 97.98th | v3 (v2023.03.01) |
| Apr 11, 2024 | 2.28% (0.02281) | 89.47th | v3 (v2023.03.01) |
| Apr 10, 2024 | 0.19% (0.00192) | 56.25th | v3 (v2023.03.01) |
| May 25, 2023 | 2.28% (0.02281) | 88.03th | v3 (v2023.03.01) |
| May 24, 2023 | 0.19% (0.00192) | 55.56th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.28% (0.02281) | 87.90th | v3 (v2023.03.01) |
| Mar 6, 2023 | 5.68% (0.05685) | 90.29th | v2 (v2022.01.01) |
| Apr 1, 2022 | 5.68% (0.05685) | 89.34th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.68% (0.05685) | 76.90th | v2 (v2022.01.01) |
No CWE recorded.
References (12)
- http://blog.trendmicro.com/trendlabs-security-intelligence/an-analysis-of-a-windows-kernel-mode-vulnerability-cve-2014-4113/ x_refsource_MISCExploitNot Applicable
- http://blogs.technet.com/b/srd/archive/2014/10/14/accessing-risk-for-the-october-2014-security-updates.aspx x_refsource_CONFIRMNot ApplicableVendor Advisory
- http://osvdb.org/show/osvdb/113167 vdb-entryx_refsource_OSVDBBroken Link
- http://packetstormsecurity.com/files/131964/Windows-8.0-8.1-x64-TrackPopupMenu-Privilege-Escalation.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/60970 third-party-advisoryx_refsource_SECUNIABroken Link
- http://www.exploit-db.com/exploits/35101 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/70364 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-058 vendor-advisoryx_refsource_MSPatchVendor Advisory
- https://github.com/sam-b/CVE-2014-4113 x_refsource_MISCThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-4113 government-resourceUS Government Resource
- https://www.exploit-db.com/exploits/37064/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/39666/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.