MSRC compact vulnerability detail

CVE-2021-1648 · Microsoft splwow64 Elevation of Privilege Vulnerability

No description was published by MSRC.

Severity
Important
Impact
Information Disclosure
CVSS
7.8 base · 7.0 temporal
Release
2021-01-12
Signals
Windows splwow64 Information Disclosure Exploited: No Publicly disclosed: Yes Exploitability: Exploitation Less Likely
CWE
No CWE data published.
Patch Diff
Loading module diff metadata...
Resolved binary override
Use this when the MSRC module name cannot be mapped automatically or the resolved binary looks wrong.
Old version New version
Description
No description was published by MSRC.
FAQ / Articles
FAQ
What type of information could be disclosed by this vulnerability? While this issue is labeled as an elevation of privilege, it can also be exploited to disclose information. The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory. This CVE is marked as Publicly Disclosed. In what way was it made public? This issue has been publicly disclosed by Google Project Zero (PZ2096) and the Zero Day Initiative (ZDI-CAN-11349 through 11351).