CVE-2014-4113 is a local privilege escalation vulnerability in the win32k.sys kernel-mode driver affecting numerous Microsoft Windows operating systems, including Windows 7, 8, 8.1, and various Server versions. This high-severity vulnerability (CVSS 7.8) allows a local user to gain elevated privileges by running a crafted application, posing a significant risk to system integrity. It has a FAUCET Risk Score of 100/100 and an exceptionally high EPSS score, indicating a strong likelihood of exploitation. The vulnerability was actively exploited in the wild in October 2014 and is listed in the KEV catalog. Multiple public exploits, including Metasploit modules and ExploitDB entries, are available, and it has garnered extensive community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.