PT-2022-2841 · Microsoft · Windows

Marcin Wiazowski

+1

·

Published

2022-04-12

·

Updated

2023-06-29

·

CVE-2022-24542

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows (affected versions not specified)
Description The issue is related to insufficient access control in the Win32k component of Windows operating systems. It can be exploited by an attacker to elevate their privileges using a specially crafted application. The vulnerability is associated with use-after-free local privilege escalation in various components of the Windows win32kfull, including UMPDDrvLineTo, UMPDDrvFontManagement, UMPDDrvStartBanding, UMPDDrvStrokeAndFillPath, UMPDDrvNextBand, UMPDDrvEscape, UMPDDrvFillPath, and UMPDDrvQueryPerBandInfo.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03393
CVE-2022-24542
ZDI-22-1022
ZDI-22-1023
ZDI-22-1024
ZDI-22-1045
ZDI-22-727
ZDI-23-459
ZDI-23-460
ZDI-23-461
ZDI-23-462

Affected Products

Windows