SB2019091033 - Privilege escalation in Microsoft Windows Text Service Framework
Published: September 10, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficient verification of data authenticity (CVE-ID: CVE-2019-1235)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due insufficient validation of input data origin within the Windows Text Service Framework (TSF) server, sent through a malicious Input Method Editor (IME). A local user can run a specially crafted application and escalate privileges on the system.
Successful exploitation of the vulnerability requires that IME is installed on the system.
Remediation
Install update from vendor's website.