vendor:
Windows
by:
Project Zero
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: Windows
Affected Version From: Windows 7
Affected Version To: Windows 10
Patch Exists: NO
Related CWE: Not specified
CPE: o:microsoft:windows
Platforms Tested: Windows
Not specified
Disclosed uninitialized kernel stack memory in Windows
The win32k!NtGdiExtGetObjectW system call in Windows 7-10 allows disclosing portions of uninitialized kernel stack memory to user-mode applications. This is possible due to leftover kernel stack data in the trailing, uninitialized bytes of the LOGFONT structure for some stock fonts, which can be read back using the GetObject() function.
Mitigation:
Apply the necessary patches and updates provided by the vendor.