7.2

CVE-2009-0078

The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows Server 2003 Updatesp1 Editionitanium
MicrosoftWindows Server 2008 Edition32_bit
MicrosoftWindows Server 2008 Editionitanium
MicrosoftWindows Vista Editionx64
MicrosoftWindows Vista Updatesp1
MicrosoftWindows Vista Versiongold
MicrosoftWindows Xp Editionpro_x64
MicrosoftWindows Xp Updatesp1
MicrosoftWindows Xp Updatesp2
MicrosoftWindows Xp Updatesp2 Editionpro_x64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.63% 0.813
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C