#VU20985 NULL pointer dereference in Windows and Windows Server - CVE-2019-1256
Published: September 10, 2019 / Updated: December 4, 2019
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a NULL pointer dereference when processing objects in memory within the Win32k component. A local user can create a malicious application, launch it on the system and execute arbitrary code with SYSTEM privileges.