Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-0078

EPSS 4.71% · P89
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2015-0078

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate the token of a calling thread, which allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft Windows Win32k 特权提升漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。win32k.sys是Windows子系统的内核部分,是一个内核模式设备驱动程序,它包含有窗口管理器、后台控制窗口和屏幕输出管理等。 Microsoft Windows内核模式驱动程序中存在特权提升漏洞,该漏洞源于内核模式驱动程序无法正确验证调用的线程令牌。攻击者可利用该漏洞获得管理员凭据,并使用该凭据提升特权,安装程序;查看、更改或删除数据;或者创建拥有完全管理权限的新帐户,运行旨在提升特权的经特殊设计的应用程序
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2015-0078

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-0078

Please Login to view more intelligence information

Same Patch Batch · n/a · 2015-03-11 · 48 CVEs total

CVE-2015-1623Microsoft Internet Explorer 内存损坏漏洞
CVE-2015-1626Microsoft Internet Explorer 内存损坏漏洞
CVE-2015-1628Microsoft Outlook Web App 跨站脚本漏洞
CVE-2015-1632Microsoft Exchange Server Outlook Web App 跨站脚本漏洞
CVE-2015-1633Microsoft SharePoint 跨站脚本漏洞
CVE-2015-1634Microsoft Internet Explorer 内存损坏漏洞
CVE-2015-1636Microsoft SharePoint 跨站脚本漏洞
CVE-2015-1067多款Apple产品Secure Transport 加密问题漏洞
CVE-2015-1631Microsoft Exchange Server伪造会议请求欺骗漏洞
CVE-2015-1624Microsoft Internet Explorer 内存损坏漏洞
CVE-2015-1625Microsoft Internet Explorer 内存损坏漏洞
CVE-2015-1622Microsoft Internet Explorer 内存损坏漏洞
CVE-2015-0100Microsoft Internet Explorer 内存损坏漏洞
CVE-2015-0099Microsoft Internet Explorer 内存损坏漏洞
CVE-2015-0097Microsoft文字本地区域远程执行代码漏洞
CVE-2015-0096Microsoft Windows DLL 远程执行代码漏洞
CVE-2015-0095Microsoft Windows内核模式驱动程序代码问题漏洞
CVE-2015-0094Microsoft Windows内核内存泄漏漏洞
CVE-2015-0093Microsoft Windows Adobe字体驱动程序远程执行代码漏洞
CVE-2015-0092Microsoft Windows Adobe字体驱动程序远程执行代码漏洞

Showing top 20 of 48 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2015-0078

No comments yet


Leave a comment