Privilege escalation in Microsoft Windows and Windows Server - CVE-2017-0189
Published: April 12, 2017
Vulnerability details
The vulnerability allows a local user to obtain elevated privileges.
The vulnerability exists due to an error in Win32k.sys driver when handling objects in memory. A local user can execute arbitrary code with SYSTEM privileges.
Successful exploitation of the vulnerability may allow a local user to elevate his privileges on the system.
Affected software
Windows Server