Microsoft Windows 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows Input Method Editor (IME) improperly handling parameters in a method of a DCOM class, aka "Windows IME Elevation of Privilege Vulnerability".
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/99404 | third party advisory vdb entry |
http://www.securitytracker.com/id/1038853 | third party advisory vdb entry |
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8566 | patch vendor advisory |