Microsoft · Windows · CVE-2018-7249
**Name of the Vulnerable Software and Affected Versions**
Microsoft Windows versions prior to KB3086255
**Description**
An issue was discovered that can cause a race condition leading to a use-after-free, allowing an unprivileged attacker to run arbitrary code in the kernel. This is achieved through two carefully timed calls to IOCTL 0xCA002813.
**Recommendations**
For Microsoft Windows versions prior to KB3086255, apply the update KB3086255 to resolve the issue.