Lucene search

K
zdiAbdelhamid NaceriZDI-22-052
HistoryJan 13, 2022 - 12:00 a.m.

Microsoft Windows EFI Partition Incorrect Authorization Denial-of-Service Vulnerability

2022-01-1300:00:00
Abdelhamid Naceri
www.zerodayinitiative.com
15

0.001 Low

EPSS

Percentile

25.4%

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Windows kernel. The issue results from improper authorization logic when accessing files in the EFI partition. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.

0.001 Low

EPSS

Percentile

25.4%