vendor:
Windows Error Reporting
by:
7.5
CVSS
HIGH
Arbitrary DACL write
CWE
Product Name: Windows Error Reporting
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows
Windows Error Reporting Arbitrary DACL write
The vulnerability allows an attacker to write arbitrary discretionary access control list (DACL) on Windows Error Reporting service. By manipulating the timing of the WER reporting queue task, an attacker can replace a file with a hardlink and gain control over the DACL. The exploit requires precise timing and may vary on different hardware setups.
Mitigation:
The vulnerability has been patched.