CVE-2015-6175

HIGH KEV

Microsoft Windows 10 Gold - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2015-6175 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 25, 2022.

Description

The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability."

References (3)

Core 3
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-135
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034334

Scores

CVSS v3 7.8
EPSS 0.0481
EPSS Percentile 89.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-05-25
VulnCheck KEV 2015-12-08
InTheWild.io 2015-12-08
ENISA EUVD EUVD-2015-6118
Status published
Products (1)
microsoft/windows_10_1507
Published Dec 09, 2015
KEV Added May 25, 2022
Tracked Since Feb 18, 2026