Untrusted Pointer Dereference in Windows and Windows Server - CVE-2021-34516
Published: July 13, 2021 / Updated: July 29, 2021
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to untrusted pointer dereference in DrvTransparentBltInternal() within the Microsoft Windows Canonical Display Driver cdd.dll. A local user can run a specially crafted program to execute arbitrary code with SYSTEM privileges.