CVE-2015-0059
Windows 7/8/8.1, Server 2008/2012, RT - Privilege Escalation via TrueType Font Parsing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-0059.
AI-analyzed exploit summary This is a functional privilege escalation exploit for CVE-2015-0003 (incorrectly referenced as CVE-2015-0059 in the query) targeting Windows kernel via WM_SYSTIMER message handling. It manipulates kernel structures to replace a process token with SYSTEM privileges, tested on multiple Windows versions (XP to 8/2008 R2).
Description
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted TrueType font, aka "TrueType Font Parsing Remote Code Execution Vulnerability."
Exploits (1)
This is a functional privilege escalation exploit for CVE-2015-0003 (incorrectly referenced as CVE-2015-0059 in the query) targeting Windows kernel via WM_SYSTIMER message handling. It manipulates kernel structures to replace a process token with SYSTEM privileges, tested on multiple Windows versions (XP to 8/2008 R2).