|CVSS SCORE||5.4, (AV:L/AC:M/Au:N/C:P/I:N/A:C)|
The specific flaw exists within the handling of ksecdd IOCTL 0x390400, which is implemented in cng.sys. Crafted parameters to this IOCTL can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM.
Microsoft has issued an update to correct this vulnerability. More details can be found at:
|CREDIT||Lucas Leong (@wmliang) of Trend Micro Security Research