High
Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a pool-based buffer overflow in the Cryptography Driver (cng.sys) in the kernel. By executing a specially-crafted program, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.
Gain Privileges
Microsoft
Refer to vendor advisory for the complete list of affected products and their respective patches.
https://bugs.chromium.org/p/project-zero/issues/detail?id=2104