Privilege escalation in Windows and Windows Server - CVE-2017-0189
Published: April 12, 2017
Windows
Windows Server
Detailed vulnerability description
The vulnerability allows a local user to obtain elevated privileges.
The vulnerability exists due to an error in Win32k.sys driver when handling objects in memory. A local user can execute arbitrary code with SYSTEM privileges.
Successful exploitation of the vulnerability may allow a local user to elevate his privileges on the system.