Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."
https://www.fireeye.com/blog/threat-research/2015/04/probable_apt28_useo.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-051
https://cloud.google.com/blog/topics/threat-intelligence/probable-apt28-useo/
https://securelist.com/a-slice-of-2017-sofacy-activity/83930/
http://www.welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-part1.pdf
http://www.welivesecurity.com/2015/07/10/sednit-apt-group-meets-hacking-team/
https://github.com/DanukaNuwan/CVE-Exploits
https://github.com/chefphenix25/vuln-rabilit-windows7
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1701
http://www.securitytracker.com/id/1032155
http://www.securityfocus.com/bid/74245