Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p36p-r3w8-8q4p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.

EPSS

Процентиль: 65%
0.00512
Низкий

7.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
почти 5 лет назад

<p>A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.</p> <p>This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation of privilege vulnerability) that is capable of leveraging the elevated privileges when code execution is attempted.</p> <p>The security update addresses the vulnerability by ensuring splwow64.exe properly handles these calls..</p>

CVSS3: 7.8
msrc
почти 5 лет назад

Microsoft splwow64 Elevation of Privilege Vulnerability

CVSS3: 7.8
fstec
почти 5 лет назад

Уязвимость процесса splwow64.exe операционной системы Windows, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 65%
0.00512
Низкий

7.8 High

CVSS3

Дефекты

CWE-269