PT-2022-6451 · Microsoft · Windows Graphics+1

Marcin Wiazowski

·

Published

2022-11-30

·

Updated

2024-05-29

·

CVE-2023-24861

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Graphics Component (affected versions not specified)
Description The issue is related to a use-after-free vulnerability in the win32kfull driver of the Microsoft Graphics component in Windows operating systems. This vulnerability is caused by the lack of checking for the existence of an object before performing operations, leading to the use of memory after it has been freed. Exploitation of this issue can allow an attacker to elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Race Condition

Use After Free

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

BDU:2023-01382
CVE-2023-24861
ZDI-23-243

Affected Products

Windows
Windows Graphics