CVE-2014-4113General(microsoft / windows_7)

LOWCVSS 7.8 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-25. Apply updates per vendor instructions.

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_7
  • windows_8
  • windows_8.1
  • windows_rt

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_7windows_8windows_8.1windows_rtwindows_rt_8.1windows_server_2003windows_server_2008windows_server_2012windows_vista

2 versions affected across 9 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-22: 1Mentions · 2026-03-23: 1Technical Details · 2026-03-22: 103-2203-23
Signal classification1 categories
General
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20131 2 - CVE-2026-22898 3 - CVE-2014-4113 4 - CVE-2026-4528 5 - CVE-2022-43555 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet merely lists trending CVEs without any further details about exploitation, vulnerability technicals, or patches.

    01020129
    1.7K followersView on X
  • DrGlitchy ⚒️⚙️@DrGlitchyTV
    General

    @dzoomer197700 @mrexits CVE-2014-4113 used by Chinese state sponsored actors. Kernel mode escalation in May 2014, around the same time as the Shadow Brokers leak. Just as strong if not stronger than the NSA's party trick. You geniunely think this kind of malware is exclusive to the NSA?

    Post summary

    The tweet asserts that CVE‑2014‑4113, a kernel‑mode escalation flaw, was used by Chinese state actors, but offers no evidence of current exploitation, patches, or detailed technical information beyond the vulnerability type.

    1000048
    248 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_7---
OSmicrosoftwindows_8---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2003---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2--
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_vista---

Explore more