Microsoft Win32k Privilege Escalation Vulnerability
Microsoft · Win32k
Date added (CISA)
2022-03-28
Remediation due
2022-04-18
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges.