ZeroHour
ZDI Published Advisoriespublished ()ingested 2

ZDI-26-606: Microsoft Windows Compatibility Appraiser Link Following Local Privilege Escalation Vulnerability

lowVulnerabilityimportance 18
AI summary · glm-5.3-flash

ZDI disclosed a link-following flaw in Windows Compatibility Appraiser (CVSS 7.0) enabling local privilege escalation from the LOCAL SERVICE context.

ZDI-26-606 describes a link-following vulnerability in the Windows Compatibility Appraiser component that permits local privilege escalation. An attacker must already be able to execute low-privileged code in the LOCAL SERVICE context on the target system. ZDI rated the issue 7.0 on the CVSS scale; the advisory lists no CVE identifier. No active exploitation is reported.

  • Link-following flaw in Compatibility Appraiser enables local privilege escalation
  • Exploitation requires prior code execution as LOCAL SERVICE
  • CVSS 7.0; no CVE id listed in the advisory
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code in the context of LOCAL SERVICE on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0.

This source does not provide full text. Read it at zerodayinitiative.com.