SB2021011223 - Privilege escalation in Microsoft Windows Kernel
Published: January 12, 2021 Updated: January 28, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-1682)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Windows Kernel within the implementation of Event Tracing for Windows. A local user can run a specially crafted program and execute arbitrary code with SYSTEM privileges.
Remediation
Install update from vendor's website.