Executive brief
A privilege escalation vulnerability in the Microsoft Windows Transaction Manager kernel-mode drivers occurs when objects in memory are improperly handled. Local attackers can exploit this via a crafted application to gain elevated privileges on the affected system.
Affected products
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1 Gold
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows RT 8.1 Gold
- Microsoft Windows 10 Gold, 1511, 1607
- Microsoft Windows Server 2016 Gold
Timeline
- 2017-03-14: patched: Microsoft released security updates.
- 2017-03-20: disclosed: Initial NVD analysis published.
- 2022-03-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- exploited: Reported as exploited in the wild.