|
Microsoft Windows is prone to an overflow condition. The 'CreateDIBPalette()' function in win32k.sys fails to properly sanitize user-supplied input resulting in a buffer overflow. By performing a clipboard operation with a crafted bitmap file containing a greater than 256 'biClrUsed' value of a 'BITMAPINFOHEADER', a local, context-dependent attacker can potentially execute arbitrary code.
|