vendor:
Windows Utility Manager
by:
Cesar Cerrudo
7.5
CVSS
HIGH
Elevation of Privileges
269
CWE
Product Name: Windows Utility Manager
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Local elevation of privileges exploit for Windows Utility Manager
This exploit allows for local elevation of privileges on Windows Utility Manager, providing a shell with system privileges. By executing specific steps, the exploit opens a file open dialog window in Windows Help and uses it to execute cmd.exe.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest security updates and patches provided by the vendor. Additionally, restricting access to the affected system and implementing the principle of least privilege can help reduce the impact of this exploit.