EXPOSURES › CVE-2014-4113
CVE-2014-4113
HIGH ⌖ ON CISA KEV · EXPLOITEDA privilege escalation vulnerability in Microsoft Win32k was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
This vulnerability in the Windows kernel (Win32k) allows an attacker to escalate privileges, potentially leading to full system compromise. DIB organizations must ensure all Windows systems are patched against known CVEs, as unpatched kernel vulnerabilities are high-value targets for ransomware and state-sponsored actors. The fact that this CVE is in the CISA KEV catalog confirms it is actively exploited in the wild, making it a critical compliance and operational risk.
Shame score — A kernel-level privilege escalation vulnerability was left unpatched long enough to be actively exploited in the wild, demonstrating a failure to patch known, high-severity CVEs and exposing organizations to severe compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |