4.6
CVE-2007-0843
- EPSS 3.61%
- Veröffentlicht 23.02.2007 02:28:00
- Zuletzt bearbeitet 16.06.2026 22:36:23
- Erkennungen
The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Vista Update beta1
Microsoft ≫ Windows Xp Edition home
Microsoft ≫ Windows Xp Update gold
Microsoft ≫ Windows Xp Update sp1 Edition 64-bit_2003
Microsoft ≫ Windows Xp Update sp1 Edition embedded
Microsoft ≫ Windows Xp Update sp1 Edition home
Microsoft ≫ Windows Xp Update sp1 Edition media_center
Microsoft ≫ Windows Xp Update sp1 Edition professional
Microsoft ≫ Windows Xp Update sp1 Edition tablet_pc
Microsoft ≫ Windows Xp Update sp2 Edition home
Microsoft ≫ Windows Xp Update sp2 Edition media_center
Microsoft ≫ Windows Xp Update sp2 Edition professional
Microsoft ≫ Windows Xp Update sp2 Edition tablet_pc
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.61% | 0.884 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052613.html
http://osvdb.org/33474
http://packetstormsecurity.com/files/163755/Microsoft-Windows-Malicious-Software-Removal-Tool-Privilege-Escalation.html
http://secunia.com/advisories/24245
http://securityreason.com/securityalert/2282
http://securityvulns.com/advisories/readdirectorychanges.asp
http://www.securityfocus.com/archive/1/460887/100/0/threaded
http://www.securityfocus.com/archive/1/460899/100/0/threaded
http://www.securityfocus.com/bid/22664
http://www.vupen.com/english/advisories/2007/0701
https://exchange.xforce.ibmcloud.com/vulnerabilities/32644