CVE-2012-0157: Input Validation
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to gain privileges via a crafted application that calls the PostMessage function, aka "PostMessage Function Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0157?
CVE-2012-0157 is rated as critical due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2012-0157?
To fix CVE-2012-0157, apply the security updates provided by Microsoft for the affected Windows versions.
Which Windows versions are affected by CVE-2012-0157?
CVE-2012-0157 affects Windows XP SP2 and SP3, Windows Vista SP2, Windows 7, Windows Server 2003 SP2, and Windows Server 2008 SP2.
Can CVE-2012-0157 be exploited remotely?
No, CVE-2012-0157 can only be exploited locally by authenticated users through a crafted application.
What is the impact of CVE-2012-0157 on system security?
CVE-2012-0157 allows local users to execute malicious code with elevated privileges, compromising system integrity.