4.6

CVE-2007-0843

Exploit
The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Vista Update beta1
Microsoft ≫ Windows Xp Edition home
Microsoft ≫ Windows Xp Update gold
Microsoft ≫ Windows Xp Update sp1 Edition 64-bit_2003
Microsoft ≫ Windows Xp Update sp1 Edition embedded
Microsoft ≫ Windows Xp Update sp1 Edition home
Microsoft ≫ Windows Xp Update sp1 Edition media_center
Microsoft ≫ Windows Xp Update sp1 Edition professional
Microsoft ≫ Windows Xp Update sp1 Edition tablet_pc
Microsoft ≫ Windows Xp Update sp2 Edition home
Microsoft ≫ Windows Xp Update sp2 Edition media_center
Microsoft ≫ Windows Xp Update sp2 Edition professional
Microsoft ≫ Windows Xp Update sp2 Edition tablet_pc
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.61% 0.884
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052613.html
http://osvdb.org/33474
http://packetstormsecurity.com/files/163755/Microsoft-Windows-Malicious-Software-Removal-Tool-Privilege-Escalation.html
http://secunia.com/advisories/24245
Vendor Advisory
http://securityreason.com/securityalert/2282
http://securityvulns.com/advisories/readdirectorychanges.asp
Vendor Advisory
http://www.securityfocus.com/archive/1/460887/100/0/threaded
http://www.securityfocus.com/archive/1/460899/100/0/threaded
http://www.securityfocus.com/bid/22664
Exploit
http://www.vupen.com/english/advisories/2007/0701
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/32644