Lucene search

K
zdiHugo Cao of SandCastle, LilangWu, Moony Li of mobile security researchZDI-22-499
HistoryMar 09, 2022 - 12:00 a.m.

Microsoft Windows CD-ROM Driver Uninitialized Pointer Privilege Escalation Vulnerability

2022-03-0900:00:00
Hugo Cao of SandCastle, LilangWu, Moony Li of mobile security research
www.zerodayinitiative.com
18

0.001 Low

EPSS

Percentile

25.4%

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the CD-ROM driver. Crafted data sent to IOCTL 0x0056c064 can trigger access to a pointer prior to initialization. An attacker can leverage this vulnerability to escalate privileges to the level of SYSTEM.