Windows Kernel-Mode Driver Vulnerability in Microsoft Products
CVE-2010-0485

7.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
8 June 2010

Summary

The affected Microsoft Windows products contain a vulnerability in the win32k.sys kernel-mode drivers, which fail to adequately validate callback parameters during window creation. This oversight permits local users to exploit the flaw, potentially leading to arbitrary code execution on the system. Such vulnerabilities can compromise system integrity and allow malicious actions to be executed without user consent.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.