>> Microsoft Windows VADs Privilege Escalation Vulnerability (MS08-064)
Title : Microsoft Windows VADs Privilege Escalation Vulnerability (MS08-064) VUPEN ID : VUPEN/ADV-2008-2815 CVE ID : CVE-2008-4036 CWE ID : CWE-189
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-10-14
Technical Description
A vulnerability has been identified in Microsoft Windows, which could be exploited by malicious users to gain elevated privileges. This issue is caused by an integer overflow error in the Memory Manager that does not properly handle memory allocation and Virtual Address Descriptors (VADs), which could allow authenticated attackers to execute arbitrary code with elevated privileges.