Untrusted Pointer Dereference in Microsoft products - CVE-2022-41121

 

Untrusted Pointer Dereference in Microsoft products - CVE-2022-41121

Published: December 13, 2022 / Updated: January 2, 2023


Vulnerability identifier: #VU70157
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41121
CWE-ID: CWE-822
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper input validation within the StretchBlt and PlgBlt graphics primitives. A local user can run a specially crafted program to trigger an untrusted pointer dereference and execute arbitrary code with SYSTEM privileges.


Affected software

Remote Desktop client for Windows Desktop
Microsoft Windows
Windows Server

How to mitigate CVE-2022-41121

Install updates from vendor's website.


External References

Related Security Bulletins