#VU49142 Buffer overflow in Windows and Windows Server - CVE-2020-17008
Published: December 24, 2020 / Updated: May 12, 2021
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the user-mode printer driver host process splwow64.exe within the Windows kernel. A local user can run a specially crafted program to trigger untrusted pointer dereference and execute arbitrary code on the system with elevated privileges.
Note, this vulnerability exists due to incomplete patch for vulnerability #VU28018.