An elevation of privilege vulnerability exists when the Windows Spatial Data Service improperly handles objects in memory. An attacker could exploit the vulnerability to overwrite or modify a protected file leading to a privilege escalation. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application. The security update addresses the vulnerability by addressing how the Windows Spatial Data Service handles objects in memory.
Jarvis_1oop of Pinduoduo Security Research Lab, Zhiniang Peng (<a href="https://twitter.com/edwardzpeng">@edwardzpeng</a>) & Haoran Qin (<a href="https://twitter.com/Q4n">@Q4n</a>)