win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Server 2008 R2 SP1 does not properly consider thread-owned objects during the processing of window handles, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-003 | vendor advisory |
http://www.securityfocus.com/bid/64725 | vdb entry third party advisory |
http://www.securitytracker.com/id/1029600 | vdb entry third party advisory |