#VU15876 Input validation error in Windows and Windows Server - CVE-2018-8550
Published: November 13, 2018 / Updated: June 17, 2021
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient validation in Windows COM Aggregate Marshaler when processing interface requests. A local unprivileged user can use this vulnerability in conjunction with another issue to execute arbitrary code on the system with elevated privileges.