Executive brief
The Microsoft Windows kernel fails to properly validate BIOS calls when 16-bit application support is enabled on 32-bit x86 platforms. Local attackers can exploit this by crafting a VDM_TIB data structure and calling NtVdmControl to trigger an improperly handled exception in the #GP trap handler (nt!KiTrap0D), resulting in local privilege escalation.
Affected products
- Microsoft Windows NT 3.1
- Microsoft Windows 2000 SP4
- Microsoft Windows XP SP2, SP3
- Microsoft Windows Server 2003 SP2
- Microsoft Windows Vista Gold, SP1, SP2
- Microsoft Windows Server 2008 Gold, SP2
- Microsoft Windows 7
Timeline
- 2010-01-20: advisory: Initial Microsoft security advisory released
- 2010-02-09: patched: Microsoft released MS10-015 to address the vulnerability
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog