CVE-2015-0057Disclosure(microsoft / windows_7)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-264

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_7
  • windows_8
  • windows_8.1
  • windows_rt

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
windows_7windows_8windows_8.1windows_rtwindows_rt_8.1windows_server_2003windows_server_2008windows_server_2012windows_vista

2 versions affected across 9 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-16: 1Technical Details · 2026-06-16: 106-16
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • OS Dev@OSdev_
    Disclosure

    One of the most interesting Windows NT kernel bugs is CVE-2015-0057 - https://blackhat.com/docs/asia-16/materials/asia-16-Wang-A-New-CVE-2015-0057-Exploit-Technology-wp.pdf The vulnerability is a use-after-free in "win32k.sys" involving "tagPROPLIST" objects. By abusing a user-mode callback at just the right moment, an attacker can force the kernel to operate on a freed object that has already been reclaimed with controlled data. The result is an arbitrary kernel read/write primitive, which is then used to replace the current process token with the SYSTEM token.

    Post summary

    The excerpt discloses details of CVE-2015-0057, a kernel use-after-free in win32k.sys that allows an attacker to obtain a SYSTEM token via an arbitrary kernel read/write primitive.

    0001761.5K
    4.8K followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_7---
OSmicrosoftwindows_8---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2003---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-itanium
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_vista---

Explore more