Lucene search

K
zdiThomas VanhoutteZDI-17-639
HistoryAug 08, 2017 - 12:00 a.m.

Microsoft Windows Error Reporting Manager Improper Access Control Privilege Escalation Vulnerability

2017-08-0800:00:00
Thomas Vanhoutte
www.zerodayinitiative.com
21

0.005 Low

EPSS

Percentile

77.5%

This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Microsoft Windows. An attacker must first obtain the ability to execute medium-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Windows Error Reporting Manager (wermgr). The issue results from the lack of proper validation of a path prior to using it in file operations. An attacker can leverage this vulnerability to delete any files accessible to SYSTEM.