Microsoft · Windows Rt · CVE-2015-2367
**Name of the Vulnerable Software and Affected Versions**
Windows Server 2003 SP2 and R2 SP2
Windows Vista SP2
Windows Server 2008 SP2 and R2 SP1
Windows 7 SP1
Windows 8
Windows 8.1
Windows Server 2012 Gold and R2
Windows RT Gold and 8.1
**Description**
The issue is related to the win32k.sys driver in the Windows operating system, which lacks protection for internal data. This allows a local attacker to obtain sensitive information from uninitialized kernel memory using a specially crafted application. The vulnerability can lead to the disclosure of memory addresses or other sensitive kernel information, potentially facilitating further system exploitation.
**Recommendations**
For Windows Server 2003 SP2 and R2 SP2, update to a newer version to mitigate the risk.
For Windows Vista SP2, update to a newer version to mitigate the risk.
For Windows Server 2008 SP2 and R2 SP1, update to a newer version to mitigate the risk.
For Windows 7 SP1, update to a newer version to mitigate the risk.
For Windows 8, update to a newer version to mitigate the risk.
For Windows 8.1, update to a newer version to mitigate the risk.
For Windows Server 2012 Gold and R2, update to a newer version to mitigate the risk.
For Windows RT Gold and 8.1, update to a newer version to mitigate the risk.
As a temporary workaround, consider restricting access to the win32k.sys driver until a patch is available.