Executive brief
An elevation of privilege vulnerability exists in the Windows Win32k component due to improper handling of objects in memory. A local attacker who successfully exploits this vulnerability could execute arbitrary code in kernel mode, granting them full control over the affected system.
Affected products
- Microsoft Windows 10 1507, 1607, 1703, 1709, 1803, 1809
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 1709, 1803
- Microsoft Windows Server 2019
Timeline
- 2019-04-09: disclosed: Initial analysis by NIST
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog