Lucene search

K
zdiLe Qi ChenZDI-23-1112
HistoryAug 15, 2023 - 12:00 a.m.

Microsoft Windows Error Reporting Local Privilege Escalation Vulnerability

2023-08-1500:00:00
Le Qi Chen
www.zerodayinitiative.com
28
vulnerability
local attackers
privilege escalation
microsoft windows
unhandled exceptions
dos device
high-privileged service

0.001 Low

EPSS

Percentile

32.3%

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Furthermore, exploitation is possible only in limited circumstances. The specific flaw exists within the processing of unhandled exceptions. By redirecting a DOS device, an attacker can abuse a high-privileged service to launch an arbitrary executable. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a high-privileged service account.