PT-2021-2331 · Microsoft · Windows

Mateusz Jurczyk

·

Published

2021-03-09

·

Updated

2023-12-29

·

CVE-2021-26863

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows (affected versions not specified)
Description The issue is related to insecure privilege management in the Win32k component of the Windows operating system. It allows an attacker to elevate their privileges. There is a race condition and use-after-free vulnerability in the NtGdiGetDeviceCapsAll function of the Windows kernel.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2021-01566
CVE-2021-26863

Affected Products

Windows