Lucene search

K
zdiChenNan and RanchoIce of Tencent ZhanluLabZDI-18-947
HistoryAug 14, 2018 - 12:00 a.m.

Microsoft Windows Dxgkrnl Type Confusion Privilege Escalation Vulnerability

2018-08-1400:00:00
ChenNan and RanchoIce of Tencent ZhanluLab
www.zerodayinitiative.com
27

EPSS

0.001

Percentile

45.8%

This vulnerability allows attackers to escalate privileges on vulnerable installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within D3DKMTRender. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to escalate privileges to SYSTEM.