Microsoft Windows Server 2019
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*
A race condition vulnerability has been identified in the Windows Win32K component, specifically within the Graphics (GRFX) subsystem. This vulnerability allows an authorized attacker to locally elevate privileges. The issue arises from improper synchronization in concurrent execution using shared resources, creating a race condition that can be exploited to gain higher privileges.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.
Users can apply the security update KB5087538 for Windows Server 2019, KB5087544 for various Windows 10 versions, KB5089548 for Windows 11 versions 26H1, and KB5087420 for Windows 11 version 23H2. For Windows Server 2022, the security update KB5087545 is available. Instructions for downloading these security updates can be found on the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.