Improper input validation in Microsoft Windows and Windows Server - CVE-2017-8591
Published: August 8, 2017 / Updated: August 8, 2017
Vulnerability details
The vulnerability allows a local user to execute arbitrary code with elevated privileges.
The vulnerability exists due to an error in Windows Input Method Editor (IME) when IME improperly handles parameters in a method of a DCOM class. A local user can instantiate the DCOM class and execute arbitrary code with elevated privileges.
Affected software
Windows Server