Skip to main content

Microsoft Windows win32k.sys Memory Corruption Vulnerability

Last Update Date: 20 Dec 2011 11:09 Release Date: 20 Dec 2011 4730 Views

RISK: High Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to potentially compromise a user's system.

The vulnerability is caused due to an error in win32k.sys and can be exploited to corrupt memory via e.g. a specially crafted web page containing an IFRAME with an overly large "height" attribute viewed using the Apple Safari browser.

Successful exploitation may allow execution of arbitrary code with kernel-mode privileges.

 

NOTE: Vendor patch is currenly unavailable.


Impact

  • Remote Code Execution

System / Technologies affected

  • Windows 7

Solutions

  • Vendor patch is currenly unavailable.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link