PT-2021-4388 · Microsoft · Win32K+1
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 10 1507 versions prior to 10.0.10240.19086
Microsoft Windows 10 1607 versions prior to 10.0.14393.4704
Microsoft Windows 10 1809 versions prior to 10.0.17763.2237
Microsoft Windows 10 1909 versions prior to 10.0.18363.1854
Microsoft Windows 10 2004 versions prior to 10.0.19041.1288
Description
An elevation-of-privilege issue exists in the Win32k component (
win32kfull.sys) of the Windows operating system. The flaw is caused by a use-after-free condition, which occurs when the kernel invokes user-mode callbacks and incorrectly assumes that an object remains unchanged after the callback returns. An attacker can exploit this by modifying, freeing, or replacing the object to gain elevated privileges on the system.Recommendations
Update Microsoft Windows 10 1507 to version 10.0.10240.19086 or later.
Update Microsoft Windows 10 1607 to version 10.0.14393.4704 or later.
Update Microsoft Windows 10 1809 to version 10.0.17763.2237 or later.
Update Microsoft Windows 10 1909 to version 10.0.18363.1854 or later.
Update Microsoft Windows 10 2004 to version 10.0.19041.1288 or later.
Exploit
Fix
LPE
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Win32K
Windows