Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Windows XP SP2 및 SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 및 R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012의 커널 모드 드라이버에 포함된 win32k.sys의 EPATHOBJ::pprFlattenRec 함수는 특정 목록의 다음 객체를 가리키는 포인터를 올바르게 초기화하지 않는다. 이로 인해 로컬 사용자가 페이지 메모리의 과도한 소비를 유발한 다음 FlattenPath 함수를 여러 차례 호출하여 PATHRECORD 체인에 대한 쓰기 권한을 획득하고, 그 결과 권한을 획득할 수 있다. 이 취약점은 "Win32k Read AV Vulnerability"라고도 한다.
Microsoft Windows XP SP2 및 SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 및 R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012의 커널 모드 드라이버에 포함된 win32k.sys의 EPATHOBJ::pprFlattenRec 함수는 특정 목록의 다음 객체를 가리키는 포인터를 올바르게 초기화하지 않는다. 이로 인해 로컬 사용자가 페이지 메모리의 과도한 소비를 유발한 다음 FlattenPath 함수를 여러 차례 호출하여 PATHRECORD 체인에 대한 쓰기 권한을 획득하고, 그 결과 권한을 획득할 수 있다. 이 취약점은 "Win32k Read AV Vulnerability"라고도 한다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."