#VU7723 Improper input validation in Windows and Windows Server - CVE-2017-8591
Published: August 8, 2017 / Updated: August 8, 2017
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to execute arbitrary code with elevated privileges.
The vulnerability exists due to an error in Windows Input Method Editor (IME) when IME improperly handles parameters in a method of a DCOM class. A local user can instantiate the DCOM class and execute arbitrary code with elevated privileges.