Description: Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges.
1) The Microsoft Windows Event System does not properly validate the range of indexes when calling an array of function pointers. This can be exploited to gain escalated privileges via a specially crafted request.
2) The Microsoft Windows Event System does not properly handle per-user subscription requests. This can be exploited to gain escalated privileges via a specially crafted event subscription request.
Successful exploitation of the vulnerabilities may allow execution of arbitrary code with SYSTEM privileges.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.