Privilege escalation in Microsoft Windows and Windows Server - CVE-2014-4113
Published: January 18, 2017 / Updated: May 4, 2022
Vulnerability identifier: #VU4865
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-4113
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local attacker to obtain elevated privileges on the target system.
The weakness exists due to improper handling of objects in memory by kernel-mode driver (win32k.sys). A local attacker can run a specially crafted application to gain elevated privileges and take complete control of the system.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
Note: the vulnerability was being actively exploited.
The weakness exists due to improper handling of objects in memory by kernel-mode driver (win32k.sys). A local attacker can run a specially crafted application to gain elevated privileges and take complete control of the system.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
Note: the vulnerability was being actively exploited.
Affected software
Microsoft Windows
Windows Server
Windows Server
How to mitigate CVE-2014-4113
Install update from vendor's website.
Links to Public Exploits and PoC-codes
- Exploit #6117 - Microsoft Windows - Net-NTLMv2 Reflection DCOM/RPC (Metasploit) (June 17, 2021)
- Exploit #6075 - Microsoft Windows 8.1/ Server 2012 - 'Win32k.sys' Local Privilege Escalation (MS14-058) (June 17, 2021)
- Exploit #3088 - winmagic_sd (Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520) (July 15, 2020)
- Exploit #2799 - WindowsExploitationResources (Resources pertaining to advanced Windows exploit development and semi-related topics) (June 2, 2020)
- Exploit #2269 - Exploit-CVE-2014-4113 (Exploit CVE-2014-4113) (April 7, 2020)
- Exploit #1872 - CVE-2014-4113 (Trigger and exploit code for CVE-2014-4113) (March 18, 2020)
- Exploit #801 - Microsoft Windows Kernel - 'win32k.sys' Privilege Escalation (MS14-058) (March 18, 2020)
- Exploit #802 - Microsoft Windows 8.0/8.1 (x64) - 'TrackPopupMenu' Privilege Escalation (MS14-058) (March 18, 2020)
- Exploit #803 - Microsoft Windows - TrackPopupMenu Win32k Null Pointer Dereference (MS14-058) (Metasploit) (March 18, 2020)
- Exploit #1612 - Windows TrackPopupMenu Win32k NULL Pointer Dereference (March 18, 2020)