4.6

CVE-2007-0843

Exploit

The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftWindows Vista Updatebeta1
MicrosoftWindows Xp Editionhome
MicrosoftWindows Xp Updategold
MicrosoftWindows Xp Updatesp1 Edition64-bit_2003
MicrosoftWindows Xp Updatesp1 Editionembedded
MicrosoftWindows Xp Updatesp1 Editionhome
MicrosoftWindows Xp Updatesp1 Editionmedia_center
MicrosoftWindows Xp Updatesp1 Editionprofessional
MicrosoftWindows Xp Updatesp1 Editiontablet_pc
MicrosoftWindows Xp Updatesp2 Editionhome
MicrosoftWindows Xp Updatesp2 Editionmedia_center
MicrosoftWindows Xp Updatesp2 Editionprofessional
MicrosoftWindows Xp Updatesp2 Editiontablet_pc
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.593
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P