Executive brief
A stack-based buffer overflow vulnerability exists in the RtlQueryRegistryValues function in win32k.sys. Local attackers can exploit this via a crafted REG_BINARY value for the SystemDefaultEUDCFont registry key to gain elevated privileges and bypass User Account Control (UAC).
Affected products
- Microsoft Windows XP SP2, SP3
- Microsoft Windows Server 2003 SP2
- Microsoft Windows Vista SP1, SP2
- Microsoft Windows Server 2008 Gold, SP2, R2
- Microsoft Windows 7
Timeline
- 2010-11-25: disclosed: Initial reports of zero-day flaw bypassing UAC
- 2011-02-08: patched: Microsoft released security bulletin MS11-011
- 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-28: advisory: NVD publication date