#VU15834 Buffer overflow in Windows Server and Windows - CVE-2018-8589
Published: November 13, 2018 / Updated: June 2, 2020
Windows Server
Windows
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within Win32k.sys driver. A local user can create a specially crafted application, run it on vulnerable system and execute code withe superuser privileges.
Note: this vulnerability is being actively exploited in limited targeted attacks.