Microsoft Windows User Access Control (UAC) Bypass Local Privilege Escalation

  Bookmark
 and Share

Microsoft Windows is exposed to a local privilege escalation issue that affects the "RtlQueryRegistryValues()" API function. Specifically, the size of the output value may be returned as either UNICODE_STRING or ULONG size, while the actual returned buffer size is determined by registry key type.

Ref: http://www.kb.cert.org/vuls/id/529673

10.49.1 - CVE: Not Available
Platform: Windows