vendor:
Windows 7
by:
MWR Labs
7.8
CVSS
HIGH
Win32k Elevation of Privilege
264
CWE
Product Name: Windows 7
Affected Version From: Windows 7
Affected Version To: Windows 10
Patch Exists: YES
Related CWE: CVE-2016-7255
CPE: o:microsoft:windows_7::-:professional
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
CVE-2019-0803
This exploit is a proof-of-concept (PoC) for a vulnerability in the Windows kernel (Win32k) that allows an attacker to gain elevated privileges. The vulnerability is caused by a race condition in the win32k!NtUserSetWindowLongPtr() function, which can be exploited to gain SYSTEM privileges.
Mitigation:
Microsoft has released a patch for this vulnerability.