CVE-2014-4113

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 15, 2014
Updated: Dec 20, 2024

Summary

CVE-2014-4113 is a privilege escalation vulnerability affecting multiple versions of Microsoft Windows, including Server 2003 SP2, Vista SP2, Server 2008 SP2 and R2 SP1, 7 SP1, 8, 8.1, Server 2012 Gold and R2, and RT Gold and 8.1. The issue lies in the win32k.sys component in kernel-mode drivers, allowing local users to gain elevated privileges through a crafted application. This vulnerability, also known as the "Win32k.sys Elevation of Privilege Vulnerability," was exploited in the wild in October 2014.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008
  • Microsoft Windows 7
  • Microsoft Windows Server 2003
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012

Affected Vendors

  • Microsoft