Out-of-bounds read In microsoft.native.quic.msquic.schannel
Description
MsQuic has a Remote Elevation of Privilege Vulnerability
Summary
Improper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network.
Details
Improper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame.
Patches
Fix underflow in ACK frame parsing - 1e6e999b
Impact
An attacker who successfully exploited this vulnerability could gain elevated privileges.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
nuget | 2.5.7, 2.4.18 | ||
nuget | 2.5.7, 2.4.18 |
Aliases
1. 2. 3. 4. 5.
References
1. 2.