CVE-2015-0058
Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 - Use-After-Free in win32k.sys Cursor Object
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-0058.
AI-analyzed exploit summary This exploit leverages a Windows kernel vulnerability (CVE-2015-0003) to achieve local privilege escalation by manipulating WM_SYSTIMER messages and replacing process tokens. It targets multiple Windows versions (XP/2K3/VISTA/2K8/7) and includes shellcode execution for token swapping.
Description
Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a crafted application, aka "Windows Cursor Object Double Free Vulnerability."
Exploits (1)
This exploit leverages a Windows kernel vulnerability (CVE-2015-0003) to achieve local privilege escalation by manipulating WM_SYSTIMER messages and replacing process tokens. It targets multiple Windows versions (XP/2K3/VISTA/2K8/7) and includes shellcode execution for token swapping.