Executive brief
An elevation of privilege vulnerability exists in the Windows Win32k component due to improper handling of objects in memory. A local attacker could exploit this to execute arbitrary code in kernel mode and gain full control of the affected system.
Affected products
- Microsoft Windows 7 Service Pack 1
- Microsoft Windows Server 2008 Service Pack 2
- Microsoft Windows Server 2008 R2 Service Pack 1
Timeline
- 2019-07-15: disclosed: NVD Published Date
- 2022-03-15: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-15: advisory: Advisory published date provided in report