Executive brief
An elevation of privilege vulnerability exists in the Windows kernel-mode driver Win32k.sys due to improper handling of calls. A local attacker could exploit this to execute code with SYSTEM privileges.
Affected products
- Microsoft Windows 7 Service Pack 1
- Microsoft Windows Server 2008 Service Pack 2
- Microsoft Windows Server 2008 R2 Service Pack 1
Timeline
- 2018-11-13: disclosed: NVD Published Date
- 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog