A privilege escalation vulnerability exists in the way that Microsoft Windows starts applications with specially crafted file manifests which could allow a logged on user to take complete control of the system.
A privilege escalation vulnerability has been reported which is caused due to the improper processing and management of file manifests by the Client-Server Run-time Subsystem.
Csrss client/server run-time subsystem is the user-mode portion of the Win32 subsystem and is an essential subsystem that must be running at all times. It is responsible for console windows, creating and/or deleting threads.
An attacker who successfully exploited this vulnerability could take complete control of an affected system. To attempt to exploit this vulnerability, an attacker must be able to log on locally to the system and run a specially crafted application.
The information provided herein is on "as is" basis, without warranty of any kind.