Executive brief
An elevation of privilege vulnerability exists in the Windows Win32k component due to improper handling of objects in memory. A local attacker could exploit this to gain elevated privileges on a targeted system. The vulnerability has been observed being used in targeted attacks in the wild.
Affected products
- Microsoft Windows 7
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows 10
- Microsoft Windows Server 2008
- Microsoft Windows Server 2008 R2
- Microsoft Windows Server 2012
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
- Microsoft Windows Server 1709
- Microsoft Windows Server 1803
Timeline
- 2018-10-09: patched: MSRC advisory published and patch released.
- 2022-01-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-01-21: disclosed: NVD publication date.