PT-2021-2385 · Microsoft · Windows
Marcin Wiazowski
·
Published
2021-03-09
·
Updated
2023-12-29
·
CVE-2021-27077
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows (affected versions not specified)
Description
The issue is related to insufficient access control in the Win32k component of Windows operating systems. Exploitation of this issue may allow an attacker to elevate their privileges using a specially crafted application. The vulnerability is associated with untrusted pointer dereferences in various functions, including
MulStrokeAndFillPath, MulFillPath, MulStretchBlt, MulLineTo, bStretch, MulDrawStream, MulTextOut, MulAlphaBlend, MulGradientFill, MulStrokePath, and MulTransparentBlt. This can potentially affect the system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows