9

CVE-2008-1436

Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows-nt Versionvista Updatesp1 Editionx64
MicrosoftWindows-nt Versionvista Updatesp2
MicrosoftWindows-nt Versionvista Updatesp2 Editionx64
MicrosoftWindows Server 2003 Updatesp1 Editionitanium
MicrosoftWindows Server 2008 Editionitanium
MicrosoftWindows Vista Editionx64
MicrosoftWindows Vista Version- Updatesp1
MicrosoftWindows Xp Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 62.97% 0.983
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C