Today we released a security update rated Important for CVE-2010-1255 in MS10-032. This vulnerability affects the win32k.sys driver. This blog post provides more information about this vulnerability that can help with prioritizing the deployment of updates this month.
What’s the risk?
A local attacker could write a custom user-mode attack application that passes a bad buffer to win32k.