High · published July 14, 2021
CVSS calls it high at 7.8. It is confirmed in active exploitation. It sits in the 90.9th percentile for exploit probability.
⚡ An elevation of privilege vulnerability in the Windows Kernel is making waves, and attackers are eyeing it like a kid in a candy store! Think of it as a backstage pass to a concert. While regular ticket holders can see the show, an attacker exploiting this flaw can stroll right into the VIP area, accessing all the goodies without permission! If successfully exploited, a malicious actor could gain higher-level access, allowing them to modify system settings, install malicious software, or even take complete control of the system. It's the digital equivalent of someone sneaking into the tech command center and having the ability to pull all the strings!
Think of it as a backstage pass to a concert. While regular ticket holders can see the show, an attacker exploiting this flaw can stroll right into the VIP area, accessing all the goodies without permission! This vulnerability resides in the Windows Kernel, where it fails to properly handle objects in memory. This allows a user to elevate their privileges, gaining unauthorized access to sensitive system functions.
If successfully exploited, a malicious actor could gain higher-level access, allowing them to modify system settings, install malicious software, or even take complete control of the system. It's the digital equivalent of someone sneaking into the tech command center and having the ability to pull all the strings! Immediate actions include applying the latest security patch from Microsoft to remedy this vulnerability. Also, ensure that you have a robust security policy in place, including regular system updates and monitoring for suspicious activity. You've got this! With a swift update and vigilant practices, you'll be securing your system in no time! 🛡️
| Product | Versions | Fixed in |
|---|---|---|
| microsoft/windows_10_1507 | < 10.0.10240.19003 | 10.0.10240.19003 |
| microsoft/windows_10_1607 | < 10.0.14393.4530 | 10.0.14393.4530 |
| microsoft/windows_10_1809 | < 10.0.17763.2061 | 10.0.17763.2061 |
| microsoft/windows_10_1909 | < 10.0.18363.1679 | 10.0.18363.1679 |
| microsoft/windows_10_2004 | < 10.0.19041.1110 | 10.0.19041.1110 |
| microsoft/windows_10_20h2 | < 10.0.19042.1110 | 10.0.19042.1110 |
| microsoft/windows_10_21h1 | < 10.0.19043.1110 | 10.0.19043.1110 |
| microsoft/windows_7 | all versions | — |
| microsoft/windows_8.1 | all versions | — |
| microsoft/windows_rt_8.1 | all versions | — |
| microsoft/windows_server_2004 | < 10.0.19041.1110 | 10.0.19041.1110 |
| microsoft/windows_server_2008 | all versions | — |
| microsoft/windows_server_2008 | all versions | — |
| microsoft/windows_server_2012 | all versions | — |
| microsoft/windows_server_2012 | all versions | — |
| microsoft/windows_server_2016 | < 10.0.14393.4530 | 10.0.14393.4530 |
| microsoft/windows_server_2019 | < 10.0.17763.2061 | 10.0.17763.2061 |
| microsoft/windows_server_20h2 | < 10.0.19042.1110 | 10.0.19042.1110 |