|
|
Windows kernel: use-after-free in bGetRealizedBrush | ||||
| Reported by cevans@google.com, Jun 22 2015 | Back to list | ||||
Credit is to "Nils Sommer of bytegeist, working with Google Project Zero". I confirm a blue screen on Win 7 32-bit with special pool enabled. --- The attached testcase crashes Win 7 with Special Pool on win32k while accessing freed memory in bGetRealizedBrush​​. --- This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public.
Comment 1
by
cevans@google.com,
Jun 22 2015
,
Aug 21 2015
,
Sep 10 2015
,
Sep 21 2015
Fixed in September bulletin MS15-097. |
|||||
| ► Sign in to add a comment | |||||