Untrusted Pointer Dereference in Microsoft products - CVE-2022-41121
Published: December 13, 2022 / Updated: January 2, 2023
Windows
Windows Server
Remote Desktop client for Windows Desktop
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation within the StretchBlt and PlgBlt graphics primitives. A local user can run a specially crafted program to trigger an untrusted pointer dereference and execute arbitrary code with SYSTEM privileges.