2022-03-01 16:58:42 +08:00
..
2022-03-01 16:58:42 +08:00
2022-03-01 16:58:42 +08:00
2022-03-01 16:58:42 +08:00
2022-03-01 16:58:42 +08:00
2022-03-01 16:58:42 +08:00

CVE-2019-1458

Describe

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

ImpactVersion

Product CPU Architecture Version Update Tested
Windows 10 x64/x86 1607
Windows 10 x64/x86
Windows 7 x64/x86 SP1
Windows 8.1 x64/x86
Windows RT 8.1
Windows Server 2008 x64/x86 R2 SP1
Windows Server 2008 x64/x86 SP2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016

Patch

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1458

Utilization

CompilerEnvironment

  • VS2019V120X64 Release

Compile a good file

cve-2019-1458.exe

Test system Windows 7 SP1 x64 Direct GIF map

11

Analyze