#VU80682 Use-after-free in Windows and Windows Server - CVE-2023-38161
Published: September 12, 2023 / Updated: September 20, 2023
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the UMPDDrvRealizeBrush() method in win32kfull driver. A local user can trigger a use-after-free error and execute arbitrary code on the system with elevated privileges.