ID:6067 - Exploit for Use-after-free in Windows and Windows Server - CVE-2018-8453

 
Main Vulnerability Database Exploits ID:6067 - Exploit for Use-after-free in Windows and Windows Server - CVE-2018-8453

ID:6067 - Exploit for Use-after-free in Windows and Windows Server - CVE-2018-8453

Published: June 17, 2021


Vulnerability identifier: #VU15249
Vulnerability risk: Medium
CVE-ID: CVE-2018-8453
CWE-ID: CWE-416
Exploitation vector: Local access
Vulnerable software:
Windows
Windows Server

Link to public exploit:


Vulnerability description

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The vulnerability exists due to a use-after free error in win32kfull!xxxDestroyWindow Win32k component. A local user can run a specially crafted application, trigger memory corruption and execute arbitrary code in kernel mode.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Note: the vulnerability has been actively exploited in the wild.


Remediation

Install updates from vendor's website.