#VU51284 Untrusted Pointer Dereference in Windows and Windows Server - CVE-2021-27077
Published: March 9, 2021 / Updated: April 29, 2021
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to untrusted pointer dereference in multiple functions within win32kfull.sys driver. A local user can run a specially crafted program to trigger untrusted pointer dereference and execute arbitrary code with SYSTEM privileges.
Remediation
External links
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27077
- https://www.zerodayinitiative.com/advisories/ZDI-21-403/
- https://www.zerodayinitiative.com/advisories/ZDI-21-482/
- https://www.zerodayinitiative.com/advisories/ZDI-21-501/
- https://www.zerodayinitiative.com/advisories/ZDI-21-500/
- https://www.zerodayinitiative.com/advisories/ZDI-21-499/
- https://www.zerodayinitiative.com/advisories/ZDI-21-498/
- https://www.zerodayinitiative.com/advisories/ZDI-21-497/
- https://www.zerodayinitiative.com/advisories/ZDI-21-496/
- https://www.zerodayinitiative.com/advisories/ZDI-21-495/
- https://www.zerodayinitiative.com/advisories/ZDI-21-494/