Permissions, Privileges, and Access Controls in Windows Server and Windows - CVE-2022-37987
Published: October 11, 2022 / Updated: October 17, 2022
Windows Server
Windows
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in the Windows Client Server Run-time Subsystem (CSRSS) when performing performing a DOS device redirection. A local user can escalate privileges on the system.