vendor:
Windows
by:
Google Project Zero
7.5
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: Windows
Affected Version From: Windows
Affected Version To: Windows
Patch Exists: YES
Related CWE:
CPE: o:microsoft:windows
Platforms Tested: Windows 10 x64 with 372.54
2016
DxgkDdiEscape Handler Bounds Check Bypass
The DxgkDdiEscape handler for 0x70001b2 in Windows doesn't properly check the bounds for its variable size input, leading to a memory corruption vulnerability. This can be exploited by an attacker to execute arbitrary code or crash the system.
Mitigation:
Apply the latest security updates and patches provided by Microsoft.